Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

github логотип

GHSA-qx25-fqx8-cgm7

около 2 месяцев назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes. A malicious RDP server can send a short fragment with an oversized declared size, causing the client to read beyond the allocated buffer, resulting in an out-of-bounds read and client crash.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-67291

около 2 месяцев назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes. A malicious RDP server can send a short fragment with an oversized declared size, causing the client to read beyond the allocated buffer, resulting in an out-of-bounds read and client crash.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-67291

около 2 месяцев назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes. A malicious RDP server can send a short fragment with an oversized declared size, causing the client to read beyond the allocated buffer, resulting in an out-of-bounds read and client crash.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-67291

около 2 месяцев назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes. A malicious RDP server can send a short fragment with an oversized declared size, causing the client to read beyond the allocated buffer, resulting in an out-of-bounds read and client crash.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-67291

около 2 месяцев назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap ou ...

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-10985

3 месяца назад

Уязвимость функций update_process_glyph_fragments() и glyph_cache_fragment_put() файла libfreerdp/cache/glyph.c RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:62571

20 дней назад

Important: freerdp security update

EPSS: Низкий
rocky логотип

RLSA-2026:61379

22 дня назад

Important: freerdp security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-62571-0

21 день назад

ELSA-2026-62571-0: freerdp security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-61379-0

22 дня назад

ELSA-2026-61379-0: freerdp security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:61378

21 день назад

Important: freerdp security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-61378-0

22 дня назад

ELSA-2026-61378-0: freerdp security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-qx25-fqx8-cgm7

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes. A malicious RDP server can send a short fragment with an oversized declared size, causing the client to read beyond the allocated buffer, resulting in an out-of-bounds read and client crash.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-67291

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes. A malicious RDP server can send a short fragment with an oversized declared size, causing the client to read beyond the allocated buffer, resulting in an out-of-bounds read and client crash.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-67291

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes. A malicious RDP server can send a short fragment with an oversized declared size, causing the client to read beyond the allocated buffer, resulting in an out-of-bounds read and client crash.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-67291

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes. A malicious RDP server can send a short fragment with an oversized declared size, causing the client to read beyond the allocated buffer, resulting in an out-of-bounds read and client crash.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-67291

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap ou ...

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
fstec логотип
BDU:2026-10985

Уязвимость функций update_process_glyph_fragments() и glyph_cache_fragment_put() файла libfreerdp/cache/glyph.c RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:62571

Important: freerdp security update

20 дней назад
rocky логотип
RLSA-2026:61379

Important: freerdp security update

22 дня назад
oracle-oval логотип
ELSA-2026-62571-0

ELSA-2026-62571-0: freerdp security update (IMPORTANT)

21 день назад
oracle-oval логотип
ELSA-2026-61379-0

ELSA-2026-61379-0: freerdp security update (IMPORTANT)

22 дня назад
rocky логотип
RLSA-2026:61378

Important: freerdp security update

21 день назад
oracle-oval логотип
ELSA-2026-61378-0

ELSA-2026-61378-0: freerdp security update (IMPORTANT)

22 дня назад

Уязвимостей на страницу