CVE-2026-85090
FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane r
CVSS
5.4
Medio
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 3 sept 2026 · Última mod.: 3 sept 2026 · CWE-125
Sin historial EPSS suficiente todavía.
FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane.
- github.comhttps://github.com/FreeRDP/FreeRDP
- github.comhttps://github.com/FreeRDP/FreeRDP/blob/3.30.0/libfreerdp/primitives/prim_YUV.c
- github.comhttps://github.com/FreeRDP/FreeRDP/commit/d0a481cb74ab57bca24791fe11b89464a332d3f1
- github.comhttps://github.com/FreeRDP/FreeRDP/releases/tag/3.31.0
- github.comhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-57h7-vw2f-2f9x
- www.vulncheck.comhttps://www.vulncheck.com/advisories/freerdp-before-3.31.0-heap-out-of-bounds-read-via-avc444
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-855057.5 ALT—
———ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).5hCVE-2026-495094.4 MED—
———Out-of-bounds read vulnerability in Samsung Opensource Escargot allows Overread Buffers.
This issue affects Escargot: 25648aef19187b3f87f4d9420b8d761453ad4630.4hCVE-2026-854558.2 ALT—
———MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOOSDB port and send a crafted short packet to read memory before authentication.11hCVE-2026-854447.5 ALT—
———MOOS-IvP through 24.8.1 contains a buffer over-read vulnerability in isQuoted(), isBraced(), and isChevroned() functions that strip whitespace but index using the original string length. Attackers can send NODE_REPORT messages with leading or trailing whitespace to read past buffer bounds and access adjacent memory.11hCVE-2026-642007.8 ALT—
———There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a past the end of an allocated heap buffer during string conversion. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.12hCVE-2026-641997.8 ALT—
———There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read outside the bounds of an allocated data structure. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.12h