Количество 5
Количество 5
CVE-2026-91963
[GHSA-hw7p-5h2r-83gq: Disclosure of uninitialized heap memory in the urbdrc USB redirection path]
CVE-2026-91963
FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.
CVE-2026-91963
FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.
CVE-2026-91963
FreeRDP versions before 3.31.0 contain an uninitialized heap memory di ...
GHSA-v76r-r3hh-2mwm
FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-91963 [GHSA-hw7p-5h2r-83gq: Disclosure of uninitialized heap memory in the urbdrc USB redirection path] | CVSS3: 6.5 | 1% Низкий | 3 дня назад | |
CVE-2026-91963 FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities. | CVSS3: 8.8 | 1% Низкий | 4 дня назад | |
CVE-2026-91963 FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities. | CVSS3: 6.5 | 1% Низкий | 3 дня назад | |
CVE-2026-91963 FreeRDP versions before 3.31.0 contain an uninitialized heap memory di ... | CVSS3: 6.5 | 1% Низкий | 3 дня назад | |
GHSA-v76r-r3hh-2mwm FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities. | CVSS3: 6.5 | 1% Низкий | 3 дня назад |
Уязвимостей на страницу