Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-91959

Опубликовано: 15 сент. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transport parser. Attackers can send a malicious BIND_ACK PDU with a truncated result entry to trigger an out-of-bounds read causing process abort.

EPSS

Процентиль: 28%
0.00346
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 6.5
ubuntu
4 дня назад

[GHSA-pj8w-fh79-f438: rts_read_result length-checks 2 bytes and then reads 4]

CVSS3: 6.5
redhat
4 дня назад

FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transport parser. Attackers can send a malicious BIND_ACK PDU with a truncated result entry to trigger an out-of-bounds read causing process abort.

CVSS3: 6.5
debian
4 дня назад

FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the ...

CVSS3: 6.5
github
4 дня назад

FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transport parser. Attackers can send a malicious BIND_ACK PDU with a truncated result entry to trigger an out-of-bounds read causing process abort.

EPSS

Процентиль: 28%
0.00346
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-125
Уязвимость CVE-2026-91959