Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

ubuntu логотип

CVE-2026-44421

2 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it validates a destination rectangle that is clamped to UINT16_MAX, but then performs the copy using the original cacheEntry->width/height. This can cause a large out-of-bounds heap write and may lead to client crashes or code execution. This bug is reachable from a malicious RDP server, but only when the client has RDPGFX enabled. This vulnerability is fixed in 3.26.0.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2026-44421

2 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it validates a destination rectangle that is clamped to UINT16_MAX, but then performs the copy using the original cacheEntry->width/height. This can cause a large out-of-bounds heap write and may lead to client crashes or code execution. This bug is reachable from a malicious RDP server, but only when the client has RDPGFX enabled. This vulnerability is fixed in 3.26.0.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-44421

2 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it validates a destination rectangle that is clamped to UINT16_MAX, but then performs the copy using the original cacheEntry->width/height. This can cause a large out-of-bounds heap write and may lead to client crashes or code execution. This bug is reachable from a malicious RDP server, but only when the client has RDPGFX enabled. This vulnerability is fixed in 3.26.0.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2026-44421

2 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2026-07647

3 месяца назад

Уязвимость функции gdi_CreateSurface() RDP-клиента FreeRDP, позволяющая нарушителю выполнить произвольный код и вызвать отказ в обслуживании

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260707-73-0017

24 дня назад

Уязвимость freerdp3

CVSS3: 8.8
EPSS: Низкий
rocky логотип

RLSA-2026:36203

23 дня назад

Important: freerdp security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36203

15 дней назад

ELSA-2026-36203: freerdp security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21116-1

около 1 месяца назад

Security update for freerdp

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-44421

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it validates a destination rectangle that is clamped to UINT16_MAX, but then performs the copy using the original cacheEntry->width/height. This can cause a large out-of-bounds heap write and may lead to client crashes or code execution. This bug is reachable from a malicious RDP server, but only when the client has RDPGFX enabled. This vulnerability is fixed in 3.26.0.

CVSS3: 8.8
1%
Низкий
2 месяца назад
redhat логотип
CVE-2026-44421

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it validates a destination rectangle that is clamped to UINT16_MAX, but then performs the copy using the original cacheEntry->width/height. This can cause a large out-of-bounds heap write and may lead to client crashes or code execution. This bug is reachable from a malicious RDP server, but only when the client has RDPGFX enabled. This vulnerability is fixed in 3.26.0.

CVSS3: 8.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-44421

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it validates a destination rectangle that is clamped to UINT16_MAX, but then performs the copy using the original cacheEntry->width/height. This can cause a large out-of-bounds heap write and may lead to client crashes or code execution. This bug is reachable from a malicious RDP server, but only when the client has RDPGFX enabled. This vulnerability is fixed in 3.26.0.

CVSS3: 8.8
1%
Низкий
2 месяца назад
debian логотип
CVE-2026-44421

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 8.8
1%
Низкий
2 месяца назад
fstec логотип
BDU:2026-07647

Уязвимость функции gdi_CreateSurface() RDP-клиента FreeRDP, позволяющая нарушителю выполнить произвольный код и вызвать отказ в обслуживании

CVSS3: 8.8
1%
Низкий
3 месяца назад
redos логотип
ROS-20260707-73-0017

Уязвимость freerdp3

CVSS3: 8.8
1%
Низкий
24 дня назад
rocky логотип
RLSA-2026:36203

Important: freerdp security update

23 дня назад
oracle-oval логотип
ELSA-2026-36203

ELSA-2026-36203: freerdp security update (IMPORTANT)

15 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21116-1

Security update for freerdp

около 1 месяца назад

Уязвимостей на страницу