Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 13

Количество 13

fstec логотип

BDU:2026-10466

3 месяца назад

Уязвимость функции planar_decompress_plane_rle() RDP-клиента FreeRDP, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20260707-73-0019

24 дня назад

Уязвимость freerdp3

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2026-45700

2 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c, freerdp_bitmap_decompress_planar() validates the X destination coordinate nXDst against the caller-provided destination stride (nDstStep) even when it is writing into the internal temp buffer pTempData. An attacker can bypass the check with a large nDstStep and a large nXDst, causing planar_decompress_plane_rle() to write past the end of pTempData. This vulnerability is fixed in 3.26.0.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2026-45700

2 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c, freerdp_bitmap_decompress_planar() validates the X destination coordinate nXDst against the caller-provided destination stride (nDstStep) even when it is writing into the internal temp buffer pTempData. An attacker can bypass the check with a large nDstStep and a large nXDst, causing planar_decompress_plane_rle() to write past the end of pTempData. This vulnerability is fixed in 3.26.0.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-45700

2 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c, freerdp_bitmap_decompress_planar() validates the X destination coordinate nXDst against the caller-provided destination stride (nDstStep) even when it is writing into the internal temp buffer pTempData. An attacker can bypass the check with a large nDstStep and a large nXDst, causing planar_decompress_plane_rle() to write past the end of pTempData. This vulnerability is fixed in 3.26.0.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2026-45700

2 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 9.8
EPSS: Низкий
rocky логотип

RLSA-2026:38501

17 дней назад

Important: freerdp security update

EPSS: Низкий
rocky логотип

RLSA-2026:37207

21 день назад

Important: freerdp security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-38501

18 дней назад

ELSA-2026-38501: freerdp security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-37207

21 день назад

ELSA-2026-37207: freerdp security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:36203

23 дня назад

Important: freerdp security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36203

15 дней назад

ELSA-2026-36203: freerdp security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21116-1

около 1 месяца назад

Security update for freerdp

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-10466

Уязвимость функции planar_decompress_plane_rle() RDP-клиента FreeRDP, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
1%
Низкий
3 месяца назад
redos логотип
ROS-20260707-73-0019

Уязвимость freerdp3

CVSS3: 9.8
1%
Низкий
24 дня назад
ubuntu логотип
CVE-2026-45700

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c, freerdp_bitmap_decompress_planar() validates the X destination coordinate nXDst against the caller-provided destination stride (nDstStep) even when it is writing into the internal temp buffer pTempData. An attacker can bypass the check with a large nDstStep and a large nXDst, causing planar_decompress_plane_rle() to write past the end of pTempData. This vulnerability is fixed in 3.26.0.

CVSS3: 9.8
1%
Низкий
2 месяца назад
redhat логотип
CVE-2026-45700

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c, freerdp_bitmap_decompress_planar() validates the X destination coordinate nXDst against the caller-provided destination stride (nDstStep) even when it is writing into the internal temp buffer pTempData. An attacker can bypass the check with a large nDstStep and a large nXDst, causing planar_decompress_plane_rle() to write past the end of pTempData. This vulnerability is fixed in 3.26.0.

CVSS3: 8.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-45700

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c, freerdp_bitmap_decompress_planar() validates the X destination coordinate nXDst against the caller-provided destination stride (nDstStep) even when it is writing into the internal temp buffer pTempData. An attacker can bypass the check with a large nDstStep and a large nXDst, causing planar_decompress_plane_rle() to write past the end of pTempData. This vulnerability is fixed in 3.26.0.

CVSS3: 9.8
1%
Низкий
2 месяца назад
debian логотип
CVE-2026-45700

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 9.8
1%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:38501

Important: freerdp security update

1%
Низкий
17 дней назад
rocky логотип
RLSA-2026:37207

Important: freerdp security update

1%
Низкий
21 день назад
oracle-oval логотип
ELSA-2026-38501

ELSA-2026-38501: freerdp security update (IMPORTANT)

18 дней назад
oracle-oval логотип
ELSA-2026-37207

ELSA-2026-37207: freerdp security update (IMPORTANT)

21 день назад
rocky логотип
RLSA-2026:36203

Important: freerdp security update

23 дня назад
oracle-oval логотип
ELSA-2026-36203

ELSA-2026-36203: freerdp security update (IMPORTANT)

15 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21116-1

Security update for freerdp

около 1 месяца назад

Уязвимостей на страницу