Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-91958

Опубликовано: 15 сент. 2026
Источник: nvd
CVSS3: 6.6
EPSS Низкий

Описание

FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.

EPSS

Процентиль: 10%
0.00199
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 6.6
ubuntu
4 дня назад

[GHSA-23pf-q83q-x45r: Unbounded MonitorIds used as an array index in X11 monitor selection]

CVSS3: 6.6
redhat
4 дня назад

FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.

CVSS3: 6.6
debian
4 дня назад

FreeRDP versions before 3.31.0 fail to validate MonitorIds array value ...

CVSS3: 6.6
github
4 дня назад

FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.

EPSS

Процентиль: 10%
0.00199
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-125