FreeRDP 3.31.0 之前的版本在解析 RDP 连接文件时,未对 MonitorIds 数组的值进行验证,导致在 函数中存在无界的数组索引访问。攻击者可以构造一个包含越界的 值的恶意 RDP 文件,当在 中打开该文件时,将触发堆内存的越界读取和写入操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91949 | 9.3 CRITICAL | FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass |
| CVE-2026-91964 | 8.8 HIGH | FreeRDP 2.0.0 through 3.30.0 Heap Buffer Overflow via RoutingToken |
| CVE-2026-91955 | 7.5 HIGH | FreeRDP before 3.31.0 Denial of Service via Desktop Dimensions |
| CVE-2026-91948 | 7.5 HIGH | FreeRDP before 3.31.0 Out-of-bounds Write via SHOW_PROTOCOL |
| CVE-2026-91947 | 7.5 HIGH | FreeRDP Server before 3.31.0 Use-After-Free via DRDYNVC |
| CVE-2026-91956 | 6.5 MEDIUM | FreeRDP before 3.31.0 Out-of-Bounds Read via URBDRC |
| CVE-2026-91951 | 6.5 MEDIUM | FreeRDP 3.14.0 through 3.30.0 Out-of-bounds Write via urbdrc |
| CVE-2026-91946 | 6.5 MEDIUM | FreeRDP before 3.31.0 Information Disclosure via RDPGFX ResetGraphics |
| CVE-2026-91953 | 6.5 MEDIUM | FreeRDP before 3.31.0 Heap Buffer Overflow via LB_LOAD_BALANCE_INFO |
| CVE-2026-91961 | 6.5 MEDIUM | FreeRDP before 3.31.0 Denial of Service via URBDRC |
| CVE-2026-91963 | 6.5 MEDIUM | FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc |
| CVE-2026-91954 | 6.5 MEDIUM | FreeRDP before 3.31.0 NULL Pointer Dereference via NSCodec |
| CVE-2026-91952 | 6.5 MEDIUM | FreeRDP before 3.31.0 Denial of Service via pool_decode_rect |
| CVE-2026-91945 | 6.5 MEDIUM | FreeRDP before 3.31.0 Out-of-bounds Read via Smartcard ATR |
| CVE-2026-91960 | 6.5 MEDIUM | FreeRDP before 3.31.0 Integer Overflow Double Free |
| CVE-2026-91959 | 6.5 MEDIUM | FreeRDP before 3.31.0 Buffer Over-read via RTS Gateway |
| CVE-2026-91950 | 6.5 MEDIUM | FreeRDP before 3.31.0 Out-of-Bounds Read via UINT32 Wraparound |
| CVE-2026-91962 | 6.3 MEDIUM | FreeRDP before 3.31.0 Integer Overflow via audin Apple backends |
| CVE-2026-91957 | 3.1 LOW | FreeRDP before 3.31.0 Use-After-Free via smartcard worker |
No comments yet