CVE-2026-91964
- EPSS 0.55%
- Veröffentlicht 15.09.2026 15:18:17
- Zuletzt bearbeitet 24.09.2026 20:44:42
FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server can trigger the overflow by s...
CVE-2026-91963
- EPSS 0.64%
- Veröffentlicht 15.09.2026 15:18:16
- Zuletzt bearbeitet 23.09.2026 20:08:36
FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating A...
CVE-2026-91961
- EPSS 0.35%
- Veröffentlicht 15.09.2026 15:18:15
- Zuletzt bearbeitet 23.09.2026 20:02:24
FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails to validate OutputBufferSize before forwarding to the libusb backend. A malicious RDP server can send a control-transfer request w...
CVE-2026-91962
- EPSS 0.24%
- Veröffentlicht 15.09.2026 15:18:15
- Zuletzt bearbeitet 23.09.2026 20:04:04
FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer size computati...
CVE-2026-91960
- EPSS 0.44%
- Veröffentlicht 15.09.2026 15:18:14
- Zuletzt bearbeitet 24.09.2026 12:17:24
FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit e...
CVE-2026-91958
- EPSS 0.2%
- Veröffentlicht 15.09.2026 15:18:13
- Zuletzt bearbeitet 24.09.2026 12:17:14
FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value t...
CVE-2026-91959
- EPSS 0.35%
- Veröffentlicht 15.09.2026 15:18:13
- Zuletzt bearbeitet 24.09.2026 12:17:19
FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transport parser. Attackers can send a malicious BIND_ACK PDU with a truncated result entry to trigger an out-of-bounds read causin...
CVE-2026-91957
- EPSS 0.33%
- Veröffentlicht 15.09.2026 15:18:12
- Zuletzt bearbeitet 24.09.2026 12:17:00
FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration. Attackers can trigger thread creation failure during channel setup to cause device pointe...
CVE-2026-91955
- EPSS 0.45%
- Veröffentlicht 15.09.2026 15:18:11
- Zuletzt bearbeitet 24.09.2026 12:16:48
FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server. Attackers can send crafted RDP packets with zero or oversized dimensions to trigger d...
CVE-2026-91956
- EPSS 0.35%
- Veröffentlicht 15.09.2026 15:18:11
- Zuletzt bearbeitet 24.09.2026 12:16:54
FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function that indexes interface arrays by position instead of protocol field InterfaceNumber. A malicious RDP server can send a crafted SELECT...