Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-66401

Опубликовано: 01 авг. 2026
Источник: nvd
CVSS3: 2.1
EPSS Низкий

Описание

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attacker with a malicious USB video camera can trigger a heap read beyond allocated bounds during camera stream setup, causing denial of service.

EPSS

Процентиль: 5%
0.00151
Низкий

2.1 Low

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 2.1
debian
2 дня назад

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerabilit ...

CVSS3: 2.1
github
2 дня назад

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attacker with a malicious USB video camera can trigger a heap read beyond allocated bounds during camera stream setup, causing denial of service.

EPSS

Процентиль: 5%
0.00151
Низкий

2.1 Low

CVSS3

Дефекты

CWE-125