Количество 20
Количество 20
CVE-2026-26955
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can trigger a heap buffer overflow in FreeRDP clients using the GDI surface pipeline (e.g., `xfreerdp`) by sending an RDPGFX ClearCodec surface command with an out-of-bounds destination rectangle. The `gdi_SurfaceCommand_ClearCodec()` handler does not call `is_within_surface()` to validate the command rectangle against the destination surface dimensions, allowing attacker-controlled `cmd->left`/`cmd->top` (and subcodec rectangle offsets) to reach image copy routines that write into `surface->data` without bounds enforcement. The OOB write corrupts an adjacent `gdiGfxSurface` struct's `codecs*` pointer with attacker-controlled pixel data, and corruption of `codecs*` is sufficient to reach an indirect function pointer call (`NSC_CONTEXT.decode` at `nsc.c:500`) on a subsequent codec command — full instruction pointer (RIP) control demonstrated in exploitability harness. Us...
CVE-2026-26955
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can trigger a heap buffer overflow in FreeRDP clients using the GDI surface pipeline (e.g., `xfreerdp`) by sending an RDPGFX ClearCodec surface command with an out-of-bounds destination rectangle. The `gdi_SurfaceCommand_ClearCodec()` handler does not call `is_within_surface()` to validate the command rectangle against the destination surface dimensions, allowing attacker-controlled `cmd->left`/`cmd->top` (and subcodec rectangle offsets) to reach image copy routines that write into `surface->data` without bounds enforcement. The OOB write corrupts an adjacent `gdiGfxSurface` struct's `codecs*` pointer with attacker-controlled pixel data, and corruption of `codecs*` is sufficient to reach an indirect function pointer call (`NSC_CONTEXT.decode` at `nsc.c:500`) on a subsequent codec command — full instruction pointer (RIP) control demonstrated in exploitability harness. Us...
CVE-2026-26955
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can trigger a heap buffer overflow in FreeRDP clients using the GDI surface pipeline (e.g., `xfreerdp`) by sending an RDPGFX ClearCodec surface command with an out-of-bounds destination rectangle. The `gdi_SurfaceCommand_ClearCodec()` handler does not call `is_within_surface()` to validate the command rectangle against the destination surface dimensions, allowing attacker-controlled `cmd->left`/`cmd->top` (and subcodec rectangle offsets) to reach image copy routines that write into `surface->data` without bounds enforcement. The OOB write corrupts an adjacent `gdiGfxSurface` struct's `codecs*` pointer with attacker-controlled pixel data, and corruption of `codecs*` is sufficient to reach an indirect function pointer call (`NSC_CONTEXT.decode` at `nsc.c:500`) on a subsequent codec command — full instruction pointer (RIP) control demonstrated in exploitability harness. Users
CVE-2026-26955
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...
BDU:2026-04152
Уязвимость функции gdi_SurfaceCommand_ClearCodec() RDP-клиента FreeRDP, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
ROS-20260615-73-0016
Уязвимость freerdp3
ROS-20260615-73-0015
Уязвимость freerdp
RLSA-2026:6005
Important: freerdp security update
ELSA-2026-7292
ELSA-2026-7292: freerdp security update (IMPORTANT)
ELSA-2026-6005
ELSA-2026-6005: freerdp security update (IMPORTANT)
ELSA-2026-6004
ELSA-2026-6004: freerdp security update (IMPORTANT)
ELSA-2026-5939
ELSA-2026-5939: freerdp security update (IMPORTANT)
SUSE-SU-2026:1165-1
Security update for freerdp
SUSE-SU-2026:1164-1
Security update for freerdp2
SUSE-SU-2026:1160-1
Security update for freerdp
SUSE-SU-2026:1129-1
Security update for freerdp
SUSE-SU-2026:1398-1
Security update for freerdp
openSUSE-SU-2026:20632-1
Security update for freerdp2
ELSA-2026-19033
ELSA-2026-19033: freerdp security update (IMPORTANT)
openSUSE-SU-2026:20657-1
Security update for freerdp
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-26955 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can trigger a heap buffer overflow in FreeRDP clients using the GDI surface pipeline (e.g., `xfreerdp`) by sending an RDPGFX ClearCodec surface command with an out-of-bounds destination rectangle. The `gdi_SurfaceCommand_ClearCodec()` handler does not call `is_within_surface()` to validate the command rectangle against the destination surface dimensions, allowing attacker-controlled `cmd->left`/`cmd->top` (and subcodec rectangle offsets) to reach image copy routines that write into `surface->data` without bounds enforcement. The OOB write corrupts an adjacent `gdiGfxSurface` struct's `codecs*` pointer with attacker-controlled pixel data, and corruption of `codecs*` is sufficient to reach an indirect function pointer call (`NSC_CONTEXT.decode` at `nsc.c:500`) on a subsequent codec command — full instruction pointer (RIP) control demonstrated in exploitability harness. Us... | CVSS3: 8.8 | 1% Низкий | 5 месяцев назад | |
CVE-2026-26955 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can trigger a heap buffer overflow in FreeRDP clients using the GDI surface pipeline (e.g., `xfreerdp`) by sending an RDPGFX ClearCodec surface command with an out-of-bounds destination rectangle. The `gdi_SurfaceCommand_ClearCodec()` handler does not call `is_within_surface()` to validate the command rectangle against the destination surface dimensions, allowing attacker-controlled `cmd->left`/`cmd->top` (and subcodec rectangle offsets) to reach image copy routines that write into `surface->data` without bounds enforcement. The OOB write corrupts an adjacent `gdiGfxSurface` struct's `codecs*` pointer with attacker-controlled pixel data, and corruption of `codecs*` is sufficient to reach an indirect function pointer call (`NSC_CONTEXT.decode` at `nsc.c:500`) on a subsequent codec command — full instruction pointer (RIP) control demonstrated in exploitability harness. Us... | CVSS3: 8.8 | 1% Низкий | 5 месяцев назад | |
CVE-2026-26955 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can trigger a heap buffer overflow in FreeRDP clients using the GDI surface pipeline (e.g., `xfreerdp`) by sending an RDPGFX ClearCodec surface command with an out-of-bounds destination rectangle. The `gdi_SurfaceCommand_ClearCodec()` handler does not call `is_within_surface()` to validate the command rectangle against the destination surface dimensions, allowing attacker-controlled `cmd->left`/`cmd->top` (and subcodec rectangle offsets) to reach image copy routines that write into `surface->data` without bounds enforcement. The OOB write corrupts an adjacent `gdiGfxSurface` struct's `codecs*` pointer with attacker-controlled pixel data, and corruption of `codecs*` is sufficient to reach an indirect function pointer call (`NSC_CONTEXT.decode` at `nsc.c:500`) on a subsequent codec command — full instruction pointer (RIP) control demonstrated in exploitability harness. Users | CVSS3: 8.8 | 1% Низкий | 5 месяцев назад | |
CVE-2026-26955 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ... | CVSS3: 8.8 | 1% Низкий | 5 месяцев назад | |
BDU:2026-04152 Уязвимость функции gdi_SurfaceCommand_ClearCodec() RDP-клиента FreeRDP, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации | CVSS3: 8.8 | 1% Низкий | 6 месяцев назад | |
ROS-20260615-73-0016 Уязвимость freerdp3 | CVSS3: 8.8 | 1% Низкий | около 2 месяцев назад | |
ROS-20260615-73-0015 Уязвимость freerdp | CVSS3: 8.8 | 1% Низкий | около 2 месяцев назад | |
RLSA-2026:6005 Important: freerdp security update | 4 месяца назад | |||
ELSA-2026-7292 ELSA-2026-7292: freerdp security update (IMPORTANT) | 2 месяца назад | |||
ELSA-2026-6005 ELSA-2026-6005: freerdp security update (IMPORTANT) | 4 месяца назад | |||
ELSA-2026-6004 ELSA-2026-6004: freerdp security update (IMPORTANT) | 4 месяца назад | |||
ELSA-2026-5939 ELSA-2026-5939: freerdp security update (IMPORTANT) | 4 месяца назад | |||
SUSE-SU-2026:1165-1 Security update for freerdp | 4 месяца назад | |||
SUSE-SU-2026:1164-1 Security update for freerdp2 | 4 месяца назад | |||
SUSE-SU-2026:1160-1 Security update for freerdp | 4 месяца назад | |||
SUSE-SU-2026:1129-1 Security update for freerdp | 4 месяца назад | |||
SUSE-SU-2026:1398-1 Security update for freerdp | 4 месяца назад | |||
openSUSE-SU-2026:20632-1 Security update for freerdp2 | 3 месяца назад | |||
ELSA-2026-19033 ELSA-2026-19033: freerdp security update (IMPORTANT) | 23 дня назад | |||
openSUSE-SU-2026:20657-1 Security update for freerdp | 3 месяца назад |
Уязвимостей на страницу