Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 29

Количество 29

rocky логотип

RLSA-2026:62571

20 дней назад

Important: freerdp security update

EPSS: Низкий
rocky логотип

RLSA-2026:61379

22 дня назад

Important: freerdp security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-62571-0

21 день назад

ELSA-2026-62571-0: freerdp security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-61379-0

22 дня назад

ELSA-2026-61379-0: freerdp security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:61378

21 день назад

Important: freerdp security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-61378-0

22 дня назад

ELSA-2026-61378-0: freerdp security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2026-55194

около 1 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0.

EPSS: Низкий
redhat логотип

CVE-2026-55194

около 1 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-55194

около 1 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0.

EPSS: Низкий
debian логотип

CVE-2026-55194

около 1 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

EPSS: Низкий
fstec логотип

BDU:2026-11998

3 месяца назад

Уязвимость функции rpc_client_recv_fragment() файла libfreerdp/core/gateway/rpc_client.c RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании и выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260824-80-0009

30 дней назад

Уязвимость freerdp3

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260824-73-0010

30 дней назад

Уязвимость freerdp3

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2026-67288

около 2 месяцев назад

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process termination.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-67288

около 2 месяцев назад

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process termination.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-67288

около 2 месяцев назад

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process termination.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-67288

около 2 месяцев назад

FreeRDP before 3.29.0 contains a null pointer dereference vulnerabilit ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-hq8h-rvcv-jvh4

около 2 месяцев назад

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process termination.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-67301

около 2 месяцев назад

FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and update_message_PolygonCB() allocate a fresh points array but copy point data from the address of the order structure instead of from polygonSC->points / polygonCB->points, resulting in a client-side out-of-bounds read. A malicious or compromised RDP server sending crafted PolygonSC/PolygonCB update orders can trigger memory disclosure or a client crash.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-67301

около 2 месяцев назад

FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and update_message_PolygonCB() allocate a fresh points array but copy point data from the address of the order structure instead of from polygonSC->points / polygonCB->points, resulting in a client-side out-of-bounds read. A malicious or compromised RDP server sending crafted PolygonSC/PolygonCB update orders can trigger memory disclosure or a client crash.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2026:62571

Important: freerdp security update

20 дней назад
rocky логотип
RLSA-2026:61379

Important: freerdp security update

22 дня назад
oracle-oval логотип
ELSA-2026-62571-0

ELSA-2026-62571-0: freerdp security update (IMPORTANT)

21 день назад
oracle-oval логотип
ELSA-2026-61379-0

ELSA-2026-61379-0: freerdp security update (IMPORTANT)

22 дня назад
rocky логотип
RLSA-2026:61378

Important: freerdp security update

21 день назад
oracle-oval логотип
ELSA-2026-61378-0

ELSA-2026-61378-0: freerdp security update (IMPORTANT)

22 дня назад
ubuntu логотип
CVE-2026-55194

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0.

0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-55194

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0.

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-55194

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0.

0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-55194

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

0%
Низкий
около 1 месяца назад
fstec логотип
BDU:2026-11998

Уязвимость функции rpc_client_recv_fragment() файла libfreerdp/core/gateway/rpc_client.c RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании и выполнить произвольный код

CVSS3: 8.8
0%
Низкий
3 месяца назад
redos логотип
ROS-20260824-80-0009

Уязвимость freerdp3

CVSS3: 8.8
0%
Низкий
30 дней назад
redos логотип
ROS-20260824-73-0010

Уязвимость freerdp3

CVSS3: 8.8
0%
Низкий
30 дней назад
ubuntu логотип
CVE-2026-67288

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process termination.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-67288

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process termination.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-67288

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process termination.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-67288

FreeRDP before 3.29.0 contains a null pointer dereference vulnerabilit ...

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-hq8h-rvcv-jvh4

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process termination.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-67301

FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and update_message_PolygonCB() allocate a fresh points array but copy point data from the address of the order structure instead of from polygonSC->points / polygonCB->points, resulting in a client-side out-of-bounds read. A malicious or compromised RDP server sending crafted PolygonSC/PolygonCB update orders can trigger memory disclosure or a client crash.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-67301

FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and update_message_PolygonCB() allocate a fresh points array but copy point data from the address of the order structure instead of from polygonSC->points / polygonCB->points, resulting in a client-side out-of-bounds read. A malicious or compromised RDP server sending crafted PolygonSC/PolygonCB update orders can trigger memory disclosure or a client crash.

CVSS3: 5.9
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу