Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2026-91960

3 дня назад

[GHSA-vccg-35r5-8jrf: Stream_EnsureCapacity still overflows]

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-91960

4 дня назад

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-91960

3 дня назад

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-91960

3 дня назад

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-7w2c-f8mf-gfr7

3 дня назад

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-91960

[GHSA-vccg-35r5-8jrf: Stream_EnsureCapacity still overflows]

CVSS3: 6.5
0%
Низкий
3 дня назад
redhat логотип
CVE-2026-91960

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.

CVSS3: 6.5
0%
Низкий
4 дня назад
nvd логотип
CVE-2026-91960

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.

CVSS3: 6.5
0%
Низкий
3 дня назад
debian логотип
CVE-2026-91960

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's ...

CVSS3: 6.5
0%
Низкий
3 дня назад
github логотип
GHSA-7w2c-f8mf-gfr7

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.

CVSS3: 6.5
0%
Низкий
3 дня назад

Уязвимостей на страницу