Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 15

Количество 15

ubuntu логотип

CVE-2026-33984

4 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipped. The caller then writes count * bpp bytes of attacker-controlled pixel data into the undersized buffer, causing a heap buffer overflow. This issue has been patched in version 3.24.2.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-33984

4 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipped. The caller then writes count * bpp bytes of attacker-controlled pixel data into the undersized buffer, causing a heap buffer overflow. This issue has been patched in version 3.24.2.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-33984

4 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipped. The caller then writes count * bpp bytes of attacker-controlled pixel data into the undersized buffer, causing a heap buffer overflow. This issue has been patched in version 3.24.2.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-33984

4 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-04671

4 месяца назад

Уязвимость функции resize_vbar_entry() RDP-клиента FreeRDP, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260615-73-0040

около 2 месяцев назад

Уязвимость freerdp3

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:8945

3 месяца назад

Important: freerdp security update

EPSS: Низкий
rocky логотип

RLSA-2026:8458

3 месяца назад

Important: freerdp security update

EPSS: Низкий
rocky логотип

RLSA-2026:8457

3 месяца назад

Important: freerdp security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-8945

3 месяца назад

ELSA-2026-8945: freerdp security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-8458

4 месяца назад

ELSA-2026-8458: freerdp security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-8457

4 месяца назад

ELSA-2026-8457: freerdp security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-19349

около 1 месяца назад

ELSA-2026-19349: freerdp security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-19033

23 дня назад

ELSA-2026-19033: freerdp security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20657-1

3 месяца назад

Security update for freerdp

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-33984

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipped. The caller then writes count * bpp bytes of attacker-controlled pixel data into the undersized buffer, causing a heap buffer overflow. This issue has been patched in version 3.24.2.

CVSS3: 7.5
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-33984

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipped. The caller then writes count * bpp bytes of attacker-controlled pixel data into the undersized buffer, causing a heap buffer overflow. This issue has been patched in version 3.24.2.

CVSS3: 7.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-33984

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipped. The caller then writes count * bpp bytes of attacker-controlled pixel data into the undersized buffer, causing a heap buffer overflow. This issue has been patched in version 3.24.2.

CVSS3: 7.5
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-33984

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 7.5
0%
Низкий
4 месяца назад
fstec логотип
BDU:2026-04671

Уязвимость функции resize_vbar_entry() RDP-клиента FreeRDP, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.5
0%
Низкий
4 месяца назад
redos логотип
ROS-20260615-73-0040

Уязвимость freerdp3

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
rocky логотип
RLSA-2026:8945

Important: freerdp security update

3 месяца назад
rocky логотип
RLSA-2026:8458

Important: freerdp security update

3 месяца назад
rocky логотип
RLSA-2026:8457

Important: freerdp security update

3 месяца назад
oracle-oval логотип
ELSA-2026-8945

ELSA-2026-8945: freerdp security update (IMPORTANT)

3 месяца назад
oracle-oval логотип
ELSA-2026-8458

ELSA-2026-8458: freerdp security update (IMPORTANT)

4 месяца назад
oracle-oval логотип
ELSA-2026-8457

ELSA-2026-8457: freerdp security update (IMPORTANT)

4 месяца назад
oracle-oval логотип
ELSA-2026-19349

ELSA-2026-19349: freerdp security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-19033

ELSA-2026-19033: freerdp security update (IMPORTANT)

23 дня назад
suse-cvrf логотип
openSUSE-SU-2026:20657-1

Security update for freerdp

3 месяца назад

Уязвимостей на страницу