Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

ubuntu логотип

CVE-2026-40033

2 месяца назад

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2026-40033

2 месяца назад

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-40033

2 месяца назад

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2026-40033

2 месяца назад

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xmr8-h8p4-932m

2 месяца назад

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2026-07426

3 месяца назад

Уязвимость функции gdi_CacheToSurface() RDP-клиента FreeRDP, позволяющая нарушителю выполнить произвольный код и вызвать отказ в обслуживании

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260707-73-0014

24 дня назад

Уязвимость freerdp3

CVSS3: 8.8
EPSS: Низкий
rocky логотип

RLSA-2026:36203

23 дня назад

Important: freerdp security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36203

15 дней назад

ELSA-2026-36203: freerdp security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21116-1

около 1 месяца назад

Security update for freerdp

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-40033

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.

CVSS3: 8.8
1%
Низкий
2 месяца назад
redhat логотип
CVE-2026-40033

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.

CVSS3: 8.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-40033

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.

CVSS3: 8.8
1%
Низкий
2 месяца назад
debian логотип
CVE-2026-40033

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in ...

CVSS3: 8.8
1%
Низкий
2 месяца назад
github логотип
GHSA-xmr8-h8p4-932m

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.

CVSS3: 8.8
1%
Низкий
2 месяца назад
fstec логотип
BDU:2026-07426

Уязвимость функции gdi_CacheToSurface() RDP-клиента FreeRDP, позволяющая нарушителю выполнить произвольный код и вызвать отказ в обслуживании

CVSS3: 8.8
1%
Низкий
3 месяца назад
redos логотип
ROS-20260707-73-0014

Уязвимость freerdp3

CVSS3: 8.8
1%
Низкий
24 дня назад
rocky логотип
RLSA-2026:36203

Important: freerdp security update

23 дня назад
oracle-oval логотип
ELSA-2026-36203

ELSA-2026-36203: freerdp security update (IMPORTANT)

15 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21116-1

Security update for freerdp

около 1 месяца назад

Уязвимостей на страницу