Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Dutchypoo

#20667of 57,584
14.2Total CVSS
Vulnerabilities · 2
High
2
PT-2026-92070
7.1
2026-09-15
Freerdp · Freerdp · CVE-2026-91951
**Name of the Vulnerable Software and Affected Versions** FreeRDP versions prior to 3.31.0 **Description** An out-of-bounds write occurs in the `urbdrc` client channel's `urb send current frame number result()` function. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte write past the allocated 16-byte buffer, resulting in a denial of service when verbose asserts are enabled. **Recommendations** Update to version 3.31.0 or later.
PT-2026-92073
7.1
2026-09-15
Freerdp · Freerdp · CVE-2026-91954
**Name of the Vulnerable Software and Affected Versions** FreeRDP versions prior to 3.31.0 **Description** A null pointer dereference occurs in the `gdi surface bits` function when processing Surface Bits commands that use the NSCodec codec ID. A malicious RDP server can cause a client crash by sending a specially crafted Surface Bits command that claims to use NSCodec, regardless of whether the codec is disabled. **Recommendations** Update to version 3.31.0 or later.