Количество 9
Количество 9
CVE-2026-63652
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsnd_server_context_free to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0.
CVE-2026-63652
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsnd_server_context_free to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0.
CVE-2026-63652
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsnd_server_context_free to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0.
CVE-2026-63652
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...
BDU:2026-12000
Уязвимость функции rdpsnd_server_recv_formats() файла channels/rdpsnd/server/rdpsnd_main.c RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании
ROS-20260907-80-0097
Уязвимость freerdp3
ROS-20260907-73-0067
Уязвимость freerdp3
RLSA-2026:61378
Important: freerdp security update
ELSA-2026-61378-0
ELSA-2026-61378-0: freerdp security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-63652 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsnd_server_context_free to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0. | 0% Низкий | около 1 месяца назад | ||
CVE-2026-63652 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsnd_server_context_free to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-63652 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsnd_server_context_free to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0. | 0% Низкий | около 1 месяца назад | ||
CVE-2026-63652 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ... | 0% Низкий | около 1 месяца назад | ||
BDU:2026-12000 Уязвимость функции rdpsnd_server_recv_formats() файла channels/rdpsnd/server/rdpsnd_main.c RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
ROS-20260907-80-0097 Уязвимость freerdp3 | CVSS3: 6.5 | 0% Низкий | 16 дней назад | |
ROS-20260907-73-0067 Уязвимость freerdp3 | CVSS3: 6.5 | 0% Низкий | 16 дней назад | |
RLSA-2026:61378 Important: freerdp security update | 21 день назад | |||
ELSA-2026-61378-0 ELSA-2026-61378-0: freerdp security update (IMPORTANT) | 22 дня назад |
Уязвимостей на страницу