Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 17

Количество 17

ubuntu логотип

CVE-2026-33984

6 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipped. The caller then writes count * bpp bytes of attacker-controlled pixel data into the undersized buffer, causing a heap buffer overflow. This issue has been patched in version 3.24.2.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-33984

6 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipped. The caller then writes count * bpp bytes of attacker-controlled pixel data into the undersized buffer, causing a heap buffer overflow. This issue has been patched in version 3.24.2.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-33984

6 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipped. The caller then writes count * bpp bytes of attacker-controlled pixel data into the undersized buffer, causing a heap buffer overflow. This issue has been patched in version 3.24.2.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-33984

6 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-04671

6 месяцев назад

Уязвимость функции resize_vbar_entry() RDP-клиента FreeRDP, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260615-80-0041

3 месяца назад

Уязвимость freerdp3

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260615-73-0040

3 месяца назад

Уязвимость freerdp3

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:8945

5 месяцев назад

Important: freerdp security update

EPSS: Низкий
rocky логотип

RLSA-2026:8458

5 месяцев назад

Important: freerdp security update

EPSS: Низкий
rocky логотип

RLSA-2026:8457

5 месяцев назад

Important: freerdp security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-8945

5 месяцев назад

ELSA-2026-8945: freerdp security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-8458

5 месяцев назад

ELSA-2026-8458: freerdp security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-8457

5 месяцев назад

ELSA-2026-8457: freerdp security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-19349

3 месяца назад

ELSA-2026-19349: freerdp security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3562-1

около 1 месяца назад

Security update for freerdp

EPSS: Низкий
oracle-oval логотип

ELSA-2026-19033

2 месяца назад

ELSA-2026-19033: freerdp security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20657-1

5 месяцев назад

Security update for freerdp

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-33984

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipped. The caller then writes count * bpp bytes of attacker-controlled pixel data into the undersized buffer, causing a heap buffer overflow. This issue has been patched in version 3.24.2.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-33984

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipped. The caller then writes count * bpp bytes of attacker-controlled pixel data into the undersized buffer, causing a heap buffer overflow. This issue has been patched in version 3.24.2.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-33984

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipped. The caller then writes count * bpp bytes of attacker-controlled pixel data into the undersized buffer, causing a heap buffer overflow. This issue has been patched in version 3.24.2.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
debian логотип
CVE-2026-33984

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 7.5
0%
Низкий
6 месяцев назад
fstec логотип
BDU:2026-04671

Уязвимость функции resize_vbar_entry() RDP-клиента FreeRDP, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.5
0%
Низкий
6 месяцев назад
redos логотип
ROS-20260615-80-0041

Уязвимость freerdp3

CVSS3: 7.5
0%
Низкий
3 месяца назад
redos логотип
ROS-20260615-73-0040

Уязвимость freerdp3

CVSS3: 7.5
0%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:8945

Important: freerdp security update

5 месяцев назад
rocky логотип
RLSA-2026:8458

Important: freerdp security update

5 месяцев назад
rocky логотип
RLSA-2026:8457

Important: freerdp security update

5 месяцев назад
oracle-oval логотип
ELSA-2026-8945

ELSA-2026-8945: freerdp security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2026-8458

ELSA-2026-8458: freerdp security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2026-8457

ELSA-2026-8457: freerdp security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2026-19349

ELSA-2026-19349: freerdp security update (IMPORTANT)

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3562-1

Security update for freerdp

около 1 месяца назад
oracle-oval логотип
ELSA-2026-19033

ELSA-2026-19033: freerdp security update (IMPORTANT)

2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20657-1

Security update for freerdp

5 месяцев назад

Уязвимостей на страницу