Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

ubuntu логотип

CVE-2026-63652

около 1 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsnd_server_context_free to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0.

EPSS: Низкий
redhat логотип

CVE-2026-63652

около 1 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsnd_server_context_free to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-63652

около 1 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsnd_server_context_free to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0.

EPSS: Низкий
debian логотип

CVE-2026-63652

около 1 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

EPSS: Низкий
fstec логотип

BDU:2026-12000

3 месяца назад

Уязвимость функции rdpsnd_server_recv_formats() файла channels/rdpsnd/server/rdpsnd_main.c RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20260907-80-0097

16 дней назад

Уязвимость freerdp3

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20260907-73-0067

16 дней назад

Уязвимость freerdp3

CVSS3: 6.5
EPSS: Низкий
rocky логотип

RLSA-2026:61378

21 день назад

Important: freerdp security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-61378-0

22 дня назад

ELSA-2026-61378-0: freerdp security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-63652

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsnd_server_context_free to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0.

0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-63652

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsnd_server_context_free to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-63652

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsnd_server_context_free to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0.

0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-63652

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

0%
Низкий
около 1 месяца назад
fstec логотип
BDU:2026-12000

Уязвимость функции rdpsnd_server_recv_formats() файла channels/rdpsnd/server/rdpsnd_main.c RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
0%
Низкий
3 месяца назад
redos логотип
ROS-20260907-80-0097

Уязвимость freerdp3

CVSS3: 6.5
0%
Низкий
16 дней назад
redos логотип
ROS-20260907-73-0067

Уязвимость freerdp3

CVSS3: 6.5
0%
Низкий
16 дней назад
rocky логотип
RLSA-2026:61378

Important: freerdp security update

21 день назад
oracle-oval логотип
ELSA-2026-61378-0

ELSA-2026-61378-0: freerdp security update (IMPORTANT)

22 дня назад

Уязвимостей на страницу