Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 11

Количество 11

fstec логотип

BDU:2026-14961

4 месяца назад

Уязвимость функции rpc_recv_bind_ack_pdu() файла libfreerdp/core/gateway/rpc_bind.c RDP-клиента FreeRDP, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2026-55193

около 1 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accept a server-controlled max_xmit_frag value in libfreerdp/core/gateway/rpc_bind.c without bounding it to the 4088-byte ReceiveFragment allocation. A malicious gateway can advertise 65535 and then send a response fragment of the same length, causing rpc_channel_read in libfreerdp/core/gateway/rpc.c to write up to 65535 bytes into the smaller ReceiveFragment buffer. This can crash the client and may permit code execution through attacker-controlled heap corruption. This issue is fixed in version 3.27.0.

EPSS: Низкий
redhat логотип

CVE-2026-55193

около 1 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accept a server-controlled max_xmit_frag value in libfreerdp/core/gateway/rpc_bind.c without bounding it to the 4088-byte ReceiveFragment allocation. A malicious gateway can advertise 65535 and then send a response fragment of the same length, causing rpc_channel_read in libfreerdp/core/gateway/rpc.c to write up to 65535 bytes into the smaller ReceiveFragment buffer. This can crash the client and may permit code execution through attacker-controlled heap corruption. This issue is fixed in version 3.27.0.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-55193

около 1 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accept a server-controlled max_xmit_frag value in libfreerdp/core/gateway/rpc_bind.c without bounding it to the 4088-byte ReceiveFragment allocation. A malicious gateway can advertise 65535 and then send a response fragment of the same length, causing rpc_channel_read in libfreerdp/core/gateway/rpc.c to write up to 65535 bytes into the smaller ReceiveFragment buffer. This can crash the client and may permit code execution through attacker-controlled heap corruption. This issue is fixed in version 3.27.0.

EPSS: Низкий
debian логотип

CVE-2026-55193

около 1 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

EPSS: Низкий
redos логотип

ROS-20260824-80-0007

около 1 месяца назад

Уязвимость freerdp3

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20260824-73-0008

около 1 месяца назад

Уязвимость freerdp3

CVSS3: 9.8
EPSS: Низкий
rocky логотип

RLSA-2026:66349

13 дней назад

Important: freerdp security update

EPSS: Низкий
rocky логотип

RLSA-2026:66347

13 дней назад

Important: freerdp security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-66349-0

13 дней назад

ELSA-2026-66349-0: freerdp security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-66347-0

14 дней назад

ELSA-2026-66347-0: freerdp security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-14961

Уязвимость функции rpc_recv_bind_ack_pdu() файла libfreerdp/core/gateway/rpc_bind.c RDP-клиента FreeRDP, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-55193

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accept a server-controlled max_xmit_frag value in libfreerdp/core/gateway/rpc_bind.c without bounding it to the 4088-byte ReceiveFragment allocation. A malicious gateway can advertise 65535 and then send a response fragment of the same length, causing rpc_channel_read in libfreerdp/core/gateway/rpc.c to write up to 65535 bytes into the smaller ReceiveFragment buffer. This can crash the client and may permit code execution through attacker-controlled heap corruption. This issue is fixed in version 3.27.0.

0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-55193

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accept a server-controlled max_xmit_frag value in libfreerdp/core/gateway/rpc_bind.c without bounding it to the 4088-byte ReceiveFragment allocation. A malicious gateway can advertise 65535 and then send a response fragment of the same length, causing rpc_channel_read in libfreerdp/core/gateway/rpc.c to write up to 65535 bytes into the smaller ReceiveFragment buffer. This can crash the client and may permit code execution through attacker-controlled heap corruption. This issue is fixed in version 3.27.0.

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-55193

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accept a server-controlled max_xmit_frag value in libfreerdp/core/gateway/rpc_bind.c without bounding it to the 4088-byte ReceiveFragment allocation. A malicious gateway can advertise 65535 and then send a response fragment of the same length, causing rpc_channel_read in libfreerdp/core/gateway/rpc.c to write up to 65535 bytes into the smaller ReceiveFragment buffer. This can crash the client and may permit code execution through attacker-controlled heap corruption. This issue is fixed in version 3.27.0.

0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-55193

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

0%
Низкий
около 1 месяца назад
redos логотип
ROS-20260824-80-0007

Уязвимость freerdp3

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
redos логотип
ROS-20260824-73-0008

Уязвимость freerdp3

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:66349

Important: freerdp security update

0%
Низкий
13 дней назад
rocky логотип
RLSA-2026:66347

Important: freerdp security update

0%
Низкий
13 дней назад
oracle-oval логотип
ELSA-2026-66349-0

ELSA-2026-66349-0: freerdp security update (IMPORTANT)

0%
Низкий
13 дней назад
oracle-oval логотип
ELSA-2026-66347-0

ELSA-2026-66347-0: freerdp security update (IMPORTANT)

0%
Низкий
14 дней назад

Уязвимостей на страницу