5.5

CVSS4.0

CVE-2026-25997 - FreeRDP has heap-use-after-free in xf_clipboard_format_equal

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_clipboard_format_equal` reads freed `lastSentFormats` memory because `xf_clipboard_formats_free` (called from the cliprdr channel thread during auto-reconnect) frees the array while the X11 event thread co…

πŸ“… Published: Feb. 25, 2026, 8:38 p.m. πŸ”„ Last Modified: April 17, 2026, 3 p.m.

5.5

CVSS4.0

CVE-2026-25959 - FreeRDP has heap-use-after-free in xf_cliprdr_provide_data_

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_cliprdr_provide_data_` passes freed `pDstData` to `XChangeProperty` because the cliprdr channel thread calls `xf_cliprdr_server_format_data_response` which converts and uses the clipboard data without hold…

πŸ“… Published: Feb. 25, 2026, 8:36 p.m. πŸ”„ Last Modified: April 17, 2026, 3 p.m.

9.2

CVSS4.0

CVE-2026-0542 - Remote Code Execution in ServiceNow AI Platform

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow Sandbox.Β Β Β  ServiceNow addressed this vulnerability by dep…

πŸ“… Published: Feb. 25, 2026, 8:35 p.m. πŸ”„ Last Modified: April 18, 2026, 10:45 a.m.

5.5

CVSS4.0

CVE-2026-25955 - FreeRDP has heap-use-after-free in xf_AppUpdateWindowFromSurface (stale XImage)

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reuses a cached `XImage` whose `data` pointer references a freed RDPGFX surface buffer, because `gdi_DeleteSurface` frees `surface->data` without invalidating the `appWindow->im…

πŸ“… Published: Feb. 25, 2026, 8:32 p.m. πŸ”„ Last Modified: April 17, 2026, 3 p.m.

5.5

CVSS4.0

CVE-2026-25954 - FreeRDP has heap-use-after-free in xf_rail_server_local_move_size

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_rail_server_local_move_size` dereferences a freed `xfAppWindow` pointer because `xf_rail_get_window` returns an unprotected pointer from the `railWindows` hash table, and the main thread can concurrently d…

πŸ“… Published: Feb. 25, 2026, 8:30 p.m. πŸ”„ Last Modified: April 18, 2026, 10:45 a.m.

5.5

CVSS4.0

CVE-2026-25953 - FreeRDP has heap-use-after-free in xf_AppUpdateWindowFromSurface (freed appWindow)

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reads from a freed `xfAppWindow` because the RDPGFX DVC thread obtains a bare pointer via `xf_rail_get_window` without any lifetime protection, while the main thread can concurr…

πŸ“… Published: Feb. 25, 2026, 8:27 p.m. πŸ”„ Last Modified: April 17, 2026, 3 p.m.

5.5

CVSS4.0

CVE-2026-25952 - FreeRDP has heap-use-after-free in xf_SetWindowMinMaxInfo

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWindowMinMaxInfo` dereferences a freed `xfAppWindow` pointer because `xf_rail_get_window` in `xf_rail_server_min_max_info` returns an unprotected pointer from the `railWindows` hash table, and the main …

πŸ“… Published: Feb. 25, 2026, 8:24 p.m. πŸ”„ Last Modified: April 18, 2026, 10:45 a.m.

7.5

CVSS3.1

CVE-2025-14511 - Improper Validation of Specified Quantity in Input in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted files to the container registry event endpoint under cert…

πŸ“… Published: Feb. 25, 2026, 8:05 p.m. πŸ”„ Last Modified: Feb. 28, 2026, 12:44 a.m.

8

CVSS3.1

CVE-2026-0752 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that under certain circumstances, could have allowed an unauthenticated user to inject arbitrary scripts into the Mermaid sandbox UI.

πŸ“… Published: Feb. 25, 2026, 8:05 p.m. πŸ”„ Last Modified: April 18, 2026, 10:45 a.m.

7.5

CVSS3.1

CVE-2026-1388 - Inefficient Regular Expression Complexity in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause regular expression denial of service by sending specially crafted input to a merge request endpoint under…

πŸ“… Published: Feb. 25, 2026, 8:05 p.m. πŸ”„ Last Modified: April 17, 2026, 3 p.m.
Total resulsts: 349182
Page 1436 of 34,919
Β« previous page Β» next page
Filters