Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

fstec логотип

BDU:2026-10452

3 месяца назад

Уязвимость парсера RDPEAR NDR RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260707-73-0018

24 дня назад

Уязвимость freerdp3

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2026-44422

2 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR type or ownership. When the same ref-id is reused across two pointer fields, the parser assigns the same heap object to both output fields. The generic destructor later walks each field independently and destroys/frees both pointers. This causes a malicious-server-triggerable heap use-after-free / double-free in the FreeRDP client's RDPEAR authentication-redirection path. This vulnerability is fixed in 3.26.0.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-44422

2 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR type or ownership. When the same ref-id is reused across two pointer fields, the parser assigns the same heap object to both output fields. The generic destructor later walks each field independently and destroys/frees both pointers. This causes a malicious-server-triggerable heap use-after-free / double-free in the FreeRDP client's RDPEAR authentication-redirection path. This vulnerability is fixed in 3.26.0.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-44422

2 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR type or ownership. When the same ref-id is reused across two pointer fields, the parser assigns the same heap object to both output fields. The generic destructor later walks each field independently and destroys/frees both pointers. This causes a malicious-server-triggerable heap use-after-free / double-free in the FreeRDP client's RDPEAR authentication-redirection path. This vulnerability is fixed in 3.26.0.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-44422

2 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:36203

23 дня назад

Important: freerdp security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36203

15 дней назад

ELSA-2026-36203: freerdp security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21116-1

около 1 месяца назад

Security update for freerdp

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-10452

Уязвимость парсера RDPEAR NDR RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.8
0%
Низкий
3 месяца назад
redos логотип
ROS-20260707-73-0018

Уязвимость freerdp3

CVSS3: 8.8
0%
Низкий
24 дня назад
ubuntu логотип
CVE-2026-44422

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR type or ownership. When the same ref-id is reused across two pointer fields, the parser assigns the same heap object to both output fields. The generic destructor later walks each field independently and destroys/frees both pointers. This causes a malicious-server-triggerable heap use-after-free / double-free in the FreeRDP client's RDPEAR authentication-redirection path. This vulnerability is fixed in 3.26.0.

CVSS3: 7.5
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-44422

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR type or ownership. When the same ref-id is reused across two pointer fields, the parser assigns the same heap object to both output fields. The generic destructor later walks each field independently and destroys/frees both pointers. This causes a malicious-server-triggerable heap use-after-free / double-free in the FreeRDP client's RDPEAR authentication-redirection path. This vulnerability is fixed in 3.26.0.

CVSS3: 7.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-44422

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR type or ownership. When the same ref-id is reused across two pointer fields, the parser assigns the same heap object to both output fields. The generic destructor later walks each field independently and destroys/frees both pointers. This causes a malicious-server-triggerable heap use-after-free / double-free in the FreeRDP client's RDPEAR authentication-redirection path. This vulnerability is fixed in 3.26.0.

CVSS3: 7.5
0%
Низкий
2 месяца назад
debian логотип
CVE-2026-44422

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 7.5
0%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:36203

Important: freerdp security update

23 дня назад
oracle-oval логотип
ELSA-2026-36203

ELSA-2026-36203: freerdp security update (IMPORTANT)

15 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21116-1

Security update for freerdp

около 1 месяца назад

Уязвимостей на страницу