CVE-2026-91954
- EPSS 0.35%
- Veröffentlicht 15.09.2026 15:18:10
- Zuletzt bearbeitet 24.09.2026 12:16:39
FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits commands with NSCodec codec ID. A malicious RDP server can crash a FreeRDP client by sending a crafted Surface Bits command claim...
CVE-2026-91952
- EPSS 0.35%
- Veröffentlicht 15.09.2026 15:18:09
- Zuletzt bearbeitet 24.09.2026 12:15:29
FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444...
CVE-2026-91953
- EPSS 0.42%
- Veröffentlicht 15.09.2026 15:18:09
- Zuletzt bearbeitet 24.09.2026 12:16:27
FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fails to validate the LB_LOAD_BALANCE_INFO field length before writing to a fixed 512-byte buffer. A malicious RDP server or man-in-th...
CVE-2026-91951
- EPSS 0.35%
- Veröffentlicht 15.09.2026 15:18:08
- Zuletzt bearbeitet 24.09.2026 12:15:20
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte ...
CVE-2026-91949
- EPSS 0.45%
- Veröffentlicht 15.09.2026 15:18:07
- Zuletzt bearbeitet 24.09.2026 12:14:46
FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, r...
CVE-2026-91950
- EPSS 0.45%
- Veröffentlicht 15.09.2026 15:18:07
- Zuletzt bearbeitet 24.09.2026 12:15:06
FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malicious RDP server can send a crafted RDPDR packet with computerNameLen se...
CVE-2026-91948
- EPSS 0.65%
- Veröffentlicht 15.09.2026 15:18:06
- Zuletzt bearbeitet 17.09.2026 12:18:29
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer unde...
CVE-2026-91946
- EPSS 0.43%
- Veröffentlicht 15.09.2026 15:18:05
- Zuletzt bearbeitet 24.09.2026 12:14:07
FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memo...
CVE-2026-91947
- EPSS 0.3%
- Veröffentlicht 15.09.2026 15:18:05
- Zuletzt bearbeitet 24.09.2026 20:44:42
FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRD...
CVE-2026-91945
- EPSS 0.57%
- Veröffentlicht 15.09.2026 15:18:04
- Zuletzt bearbeitet 24.09.2026 12:13:45
FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to validate ATR length fields against fixed inline arrays. Authenticated RDP clients can send oversized ATR lengths in PAKID_CORE_DEVI...