Количество 5
Количество 5
CVE-2026-91951
[GHSA-h5w2-q35j-443h: Out-of-bounds write in urb_send_current_frame_number_result]
CVE-2026-91951
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte write past the allocated 16-byte buffer, causing denial of service when verbose asserts are enabled.
CVE-2026-91951
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte write past the allocated 16-byte buffer, causing denial of service when verbose asserts are enabled.
CVE-2026-91951
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerab ...
GHSA-8rv4-fc8j-9xvc
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte write past the allocated 16-byte buffer, causing denial of service when verbose asserts are enabled.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-91951 [GHSA-h5w2-q35j-443h: Out-of-bounds write in urb_send_current_frame_number_result] | CVSS3: 6.5 | 0% Низкий | 4 дня назад | |
CVE-2026-91951 FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte write past the allocated 16-byte buffer, causing denial of service when verbose asserts are enabled. | CVSS3: 6.5 | 0% Низкий | 4 дня назад | |
CVE-2026-91951 FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte write past the allocated 16-byte buffer, causing denial of service when verbose asserts are enabled. | CVSS3: 6.5 | 0% Низкий | 4 дня назад | |
CVE-2026-91951 FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerab ... | CVSS3: 6.5 | 0% Низкий | 4 дня назад | |
GHSA-8rv4-fc8j-9xvc FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte write past the allocated 16-byte buffer, causing denial of service when verbose asserts are enabled. | CVSS3: 6.5 | 0% Низкий | 4 дня назад |
Уязвимостей на страницу