Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Baixingyuu

#20707of 57,584
14.2Total CVSS
Vulnerabilities · 2
High
2
PT-2026-92069
7.1
2026-09-15
Freerdp · Freerdp · CVE-2026-91950
**Name of the Vulnerable Software and Affected Versions** FreeRDP versions prior to 3.31.0 **Description** An out-of-bounds read occurs in the `rdpdr dump packet()` function due to a 32-bit unsigned integer wraparound during buffer bounds validation. A malicious RDP server can send a crafted RDPDR packet with the `computerNameLen` variable set to 0xFFFFFFF0 to bypass security checks. This allows memory reads beyond the packet buffer, which can lead to client crashes or the disclosure of heap memory in logs. **Recommendations** Update to version 3.31.0 or later.
PT-2026-92075
7.1
2026-09-15
Freerdp · Freerdp · CVE-2026-91956
**Name of the Vulnerable Software and Affected Versions** FreeRDP versions prior to 3.31.0 **Description** An out-of-bounds read occurs in the `func get ep desc()` function within the URBDRC channel. The issue arises because interface arrays are indexed by position rather than by the protocol field `InterfaceNumber`. A malicious RDP server can trigger this by sending a crafted SELECT CONFIGURATION message with permuted `InterfaceNumber` values, allowing the server to read past allocated heap memory and cause the client to crash. **Recommendations** Update FreeRDP to version 3.31.0 or later.