Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 13

Количество 13

ubuntu логотип

CVE-2026-64624

2 месяца назад

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-64624

2 месяца назад

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2026-64624

2 месяца назад

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-64624

2 месяца назад

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP ...

CVSS3: 7.8
EPSS: Низкий
redos логотип

ROS-20260904-80-0039

19 дней назад

Уязвимость freerdp3

CVSS3: 8.4
EPSS: Низкий
redos логотип

ROS-20260904-73-0014

19 дней назад

Уязвимость freerdp3

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-4vxc-ggfg-5366

2 месяца назад

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.

CVSS3: 7.8
EPSS: Низкий
rocky логотип

RLSA-2026:54487

около 1 месяца назад

Important: freerdp security update

EPSS: Низкий
rocky логотип

RLSA-2026:54485

около 1 месяца назад

Important: freerdp security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-54487

около 1 месяца назад

ELSA-2026-54487: freerdp security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-54485

около 1 месяца назад

ELSA-2026-54485: freerdp security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:54486

около 1 месяца назад

Important: freerdp security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-54486

около 1 месяца назад

ELSA-2026-54486: freerdp security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-64624

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.

CVSS3: 7.8
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-64624

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.

CVSS3: 7.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-64624

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.

CVSS3: 7.8
0%
Низкий
2 месяца назад
debian логотип
CVE-2026-64624

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP ...

CVSS3: 7.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260904-80-0039

Уязвимость freerdp3

CVSS3: 8.4
0%
Низкий
19 дней назад
redos логотип
ROS-20260904-73-0014

Уязвимость freerdp3

CVSS3: 8.4
0%
Низкий
19 дней назад
github логотип
GHSA-4vxc-ggfg-5366

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.

CVSS3: 7.8
0%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:54487

Important: freerdp security update

около 1 месяца назад
rocky логотип
RLSA-2026:54485

Important: freerdp security update

около 1 месяца назад
oracle-oval логотип
ELSA-2026-54487

ELSA-2026-54487: freerdp security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-54485

ELSA-2026-54485: freerdp security update (IMPORTANT)

около 1 месяца назад
rocky логотип
RLSA-2026:54486

Important: freerdp security update

около 1 месяца назад
oracle-oval логотип
ELSA-2026-54486

ELSA-2026-54486: freerdp security update (IMPORTANT)

около 1 месяца назад

Уязвимостей на страницу