FreeRDP 3.31.0 之前的版本中, 函数存在堆缓冲区溢出漏洞。该函数在将数据写入固定的 512 字节缓冲区之前,未验证 字段的长度。恶意的 RDP 服务器或中间人攻击者可以发送一个携带过大 值的服务器重定向 PDU,从而用攻击者可控的内容导致缓冲区溢出,进而在认证完成前造成拒绝服务或堆内存损坏。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91949 | 9.3 CRITICAL | FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass |
| CVE-2026-91964 | 8.8 HIGH | FreeRDP 2.0.0 through 3.30.0 Heap Buffer Overflow via RoutingToken |
| CVE-2026-91948 | 7.5 HIGH | FreeRDP before 3.31.0 Out-of-bounds Write via SHOW_PROTOCOL |
| CVE-2026-91947 | 7.5 HIGH | FreeRDP Server before 3.31.0 Use-After-Free via DRDYNVC |
| CVE-2026-91955 | 7.5 HIGH | FreeRDP before 3.31.0 Denial of Service via Desktop Dimensions |
| CVE-2026-91958 | 6.6 MEDIUM | FreeRDP 3.11.0 through 3.30.0 Heap Buffer Overflow via Monitor Index |
| CVE-2026-91960 | 6.5 MEDIUM | FreeRDP before 3.31.0 Integer Overflow Double Free |
| CVE-2026-91945 | 6.5 MEDIUM | FreeRDP before 3.31.0 Out-of-bounds Read via Smartcard ATR |
| CVE-2026-91952 | 6.5 MEDIUM | FreeRDP before 3.31.0 Denial of Service via pool_decode_rect |
| CVE-2026-91959 | 6.5 MEDIUM | FreeRDP before 3.31.0 Buffer Over-read via RTS Gateway |
| CVE-2026-91954 | 6.5 MEDIUM | FreeRDP before 3.31.0 NULL Pointer Dereference via NSCodec |
| CVE-2026-91963 | 6.5 MEDIUM | FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc |
| CVE-2026-91961 | 6.5 MEDIUM | FreeRDP before 3.31.0 Denial of Service via URBDRC |
| CVE-2026-91950 | 6.5 MEDIUM | FreeRDP before 3.31.0 Out-of-Bounds Read via UINT32 Wraparound |
| CVE-2026-91946 | 6.5 MEDIUM | FreeRDP before 3.31.0 Information Disclosure via RDPGFX ResetGraphics |
| CVE-2026-91951 | 6.5 MEDIUM | FreeRDP 3.14.0 through 3.30.0 Out-of-bounds Write via urbdrc |
| CVE-2026-91956 | 6.5 MEDIUM | FreeRDP before 3.31.0 Out-of-Bounds Read via URBDRC |
| CVE-2026-91962 | 6.3 MEDIUM | FreeRDP before 3.31.0 Integer Overflow via audin Apple backends |
| CVE-2026-91957 | 3.1 LOW | FreeRDP before 3.31.0 Use-After-Free via smartcard worker |
No comments yet