Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j96g-x36f-4cg4

Опубликовано: 01 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2.4
CVSS3: 2.1

Описание

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attacker with a malicious USB video camera can trigger a heap read beyond allocated bounds during camera stream setup, causing denial of service.

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attacker with a malicious USB video camera can trigger a heap read beyond allocated bounds during camera stream setup, causing denial of service.

EPSS

Процентиль: 5%
0.00151
Низкий

2.4 Low

CVSS4

2.1 Low

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 2.1
nvd
2 дня назад

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attacker with a malicious USB video camera can trigger a heap read beyond allocated bounds during camera stream setup, causing denial of service.

CVSS3: 2.1
debian
2 дня назад

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerabilit ...

EPSS

Процентиль: 5%
0.00151
Низкий

2.4 Low

CVSS4

2.1 Low

CVSS3

Дефекты

CWE-125