Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 24

Количество 24

rocky логотип

RLSA-2026:8945

5 месяцев назад

Important: freerdp security update

EPSS: Низкий
rocky логотип

RLSA-2026:8458

5 месяцев назад

Important: freerdp security update

EPSS: Низкий
rocky логотип

RLSA-2026:8457

5 месяцев назад

Important: freerdp security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-8945

5 месяцев назад

ELSA-2026-8945: freerdp security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-8458

5 месяцев назад

ELSA-2026-8458: freerdp security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-8457

5 месяцев назад

ELSA-2026-8457: freerdp security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-19349

3 месяца назад

ELSA-2026-19349: freerdp security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2026-33984

6 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipped. The caller then writes count * bpp bytes of attacker-controlled pixel data into the undersized buffer, causing a heap buffer overflow. This issue has been patched in version 3.24.2.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-33984

6 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipped. The caller then writes count * bpp bytes of attacker-controlled pixel data into the undersized buffer, causing a heap buffer overflow. This issue has been patched in version 3.24.2.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-33984

6 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipped. The caller then writes count * bpp bytes of attacker-controlled pixel data into the undersized buffer, causing a heap buffer overflow. This issue has been patched in version 3.24.2.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-33984

6 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-33983

6 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, progressive_decompress_tile_upgrade() detects a mismatch via progressive_rfx_quant_cmp_equal() but only emits WLog_WARN, execution continues. The wrapped value (247) is used as a shift exponent, causing undefined behavior and an approximately 80 billion iteration loop (CPU DoS). This issue has been patched in version 3.24.2.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-33983

6 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, progressive_decompress_tile_upgrade() detects a mismatch via progressive_rfx_quant_cmp_equal() but only emits WLog_WARN, execution continues. The wrapped value (247) is used as a shift exponent, causing undefined behavior and an approximately 80 billion iteration loop (CPU DoS). This issue has been patched in version 3.24.2.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-33983

6 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, progressive_decompress_tile_upgrade() detects a mismatch via progressive_rfx_quant_cmp_equal() but only emits WLog_WARN, execution continues. The wrapped value (247) is used as a shift exponent, causing undefined behavior and an approximately 80 billion iteration loop (CPU DoS). This issue has been patched in version 3.24.2.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-33983

6 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3562-1

около 1 месяца назад

Security update for freerdp

EPSS: Низкий
oracle-oval логотип

ELSA-2026-19033

2 месяца назад

ELSA-2026-19033: freerdp security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20657-1

5 месяцев назад

Security update for freerdp

EPSS: Низкий
fstec логотип

BDU:2026-04671

6 месяцев назад

Уязвимость функции resize_vbar_entry() RDP-клиента FreeRDP, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-04670

6 месяцев назад

Уязвимость функции progressive_decompress_tile_upgrade() RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2026:8945

Important: freerdp security update

5 месяцев назад
rocky логотип
RLSA-2026:8458

Important: freerdp security update

5 месяцев назад
rocky логотип
RLSA-2026:8457

Important: freerdp security update

5 месяцев назад
oracle-oval логотип
ELSA-2026-8945

ELSA-2026-8945: freerdp security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2026-8458

ELSA-2026-8458: freerdp security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2026-8457

ELSA-2026-8457: freerdp security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2026-19349

ELSA-2026-19349: freerdp security update (IMPORTANT)

3 месяца назад
ubuntu логотип
CVE-2026-33984

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipped. The caller then writes count * bpp bytes of attacker-controlled pixel data into the undersized buffer, causing a heap buffer overflow. This issue has been patched in version 3.24.2.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-33984

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipped. The caller then writes count * bpp bytes of attacker-controlled pixel data into the undersized buffer, causing a heap buffer overflow. This issue has been patched in version 3.24.2.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-33984

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipped. The caller then writes count * bpp bytes of attacker-controlled pixel data into the undersized buffer, causing a heap buffer overflow. This issue has been patched in version 3.24.2.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
debian логотип
CVE-2026-33984

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 7.5
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2026-33983

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, progressive_decompress_tile_upgrade() detects a mismatch via progressive_rfx_quant_cmp_equal() but only emits WLog_WARN, execution continues. The wrapped value (247) is used as a shift exponent, causing undefined behavior and an approximately 80 billion iteration loop (CPU DoS). This issue has been patched in version 3.24.2.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-33983

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, progressive_decompress_tile_upgrade() detects a mismatch via progressive_rfx_quant_cmp_equal() but only emits WLog_WARN, execution continues. The wrapped value (247) is used as a shift exponent, causing undefined behavior and an approximately 80 billion iteration loop (CPU DoS). This issue has been patched in version 3.24.2.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-33983

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, progressive_decompress_tile_upgrade() detects a mismatch via progressive_rfx_quant_cmp_equal() but only emits WLog_WARN, execution continues. The wrapped value (247) is used as a shift exponent, causing undefined behavior and an approximately 80 billion iteration loop (CPU DoS). This issue has been patched in version 3.24.2.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
debian логотип
CVE-2026-33983

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 6.5
0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:3562-1

Security update for freerdp

около 1 месяца назад
oracle-oval логотип
ELSA-2026-19033

ELSA-2026-19033: freerdp security update (IMPORTANT)

2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20657-1

Security update for freerdp

5 месяцев назад
fstec логотип
BDU:2026-04671

Уязвимость функции resize_vbar_entry() RDP-клиента FreeRDP, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.5
0%
Низкий
6 месяцев назад
fstec логотип
BDU:2026-04670

Уязвимость функции progressive_decompress_tile_upgrade() RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
0%
Низкий
6 месяцев назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.