Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Nambers

#20699of 57,584
14.2Total CVSS
Vulnerabilities · 2
High
2
PT-2026-92078
7.1
2026-09-15
Freerdp · Freerdp · CVE-2026-91959
**Name of the Vulnerable Software and Affected Versions** FreeRDP versions prior to 3.31.0 **Description** A buffer over-read occurs in the `rts read result()` function within the RPC gateway transport parser. An attacker can trigger an out-of-bounds read, leading to a process abort, by sending a malicious BIND ACK PDU (Protocol Data Unit) containing a truncated result entry. **Recommendations** Update to version 3.31.0 or later.
PT-2026-92079
7.1
2026-09-15
Freerdp · Freerdp · CVE-2026-91960
**Name of the Vulnerable Software and Affected Versions** FreeRDP versions prior to 3.31.0 **Description** An integer overflow exists in the `Stream EnsureRemainingCapacity()` function within WinPR. A remote attacker acting as a malicious RD Gateway peer can send a WebSocket Ping frame containing a crafted 64-bit extended payload length. This triggers an integer wraparound, leading to a double free—a situation where the system attempts to free the same memory location twice—which causes the FreeRDP client to crash, resulting in a denial of service. **Recommendations** Update FreeRDP to version 3.31.0 or later.