Количество 5
Количество 5
CVE-2026-91948
[GHSA-9jcm-x588-gh26: SHOW_PROTOCOL live-pointer overwrite]
CVE-2026-91948
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.
CVE-2026-91948
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.
CVE-2026-91948
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerab ...
GHSA-vg28-cmpq-3hp8
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-91948 [GHSA-9jcm-x588-gh26: SHOW_PROTOCOL live-pointer overwrite] | CVSS3: 7.5 | 1% Низкий | 4 дня назад | |
CVE-2026-91948 FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution. | CVSS3: 7.5 | 1% Низкий | 4 дня назад | |
CVE-2026-91948 FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution. | CVSS3: 7.5 | 1% Низкий | 4 дня назад | |
CVE-2026-91948 FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerab ... | CVSS3: 7.5 | 1% Низкий | 4 дня назад | |
GHSA-vg28-cmpq-3hp8 FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution. | CVSS3: 7.5 | 1% Низкий | 4 дня назад |
Уязвимостей на страницу