VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3093 CVEsRSS

CVE-2026-91946Medium· 6.5PoC
1w ago

FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format

FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitiali…

▾ Twilightfreerdp · freerdpEPSS 0.46%via NVD
CVE-2026-91952Medium· 6.5PoC
1w ago

FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size

FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send c…

▾ Twilightfreerdp · freerdpEPSS 0.39%via NVD
CVE-2026-91951Medium· 6.5PoC
1w ago

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trig…

▾ Twilightfreerdp · freerdpEPSS 0.38%via NVD
CVE-2026-91955High· 7.5PoC
1w ago

FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server

FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server. Attackers can send crafted RDP packets with zero or oversized dimensions…

▾ Midnightfreerdp · freerdpEPSS 0.57%via NVD
CVE-2026-91953Medium· 6.5PoC
1w ago

FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fails to validate the LB_LOAD_BALANCE_INFO field length before writing to a fixed 512-byte buffer

FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fails to validate the LB_LOAD_BALANCE_INFO field length before writing to a fixed 512-byte buffer. A malicious RDP server…

▾ Twilightfreerdp · freerdpEPSS 0.46%via NVD
CVE-2026-91949Critical· 9.3
1w ago

FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them

FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protoco…

▾ Midnightfreerdp · freerdpEPSS 0.56%via NVD
CVE-2026-91958Medium· 6.6PoC
1w ago

FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors

FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmon…

▾ Twilightfreerdp · freerdpEPSS 0.16%via NVD
CVE-2026-91956Medium· 6.5
1w ago

FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function that indexes interface arrays by position instead of protocol field InterfaceNumber

FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function that indexes interface arrays by position instead of protocol field InterfaceNumber. A malicious RDP server can send a c…

▾ Sunlitfreerdp · freerdpEPSS 0.38%via NVD
CVE-2026-91954Medium· 6.5
1w ago

FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits commands with NSCodec codec ID

FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits commands with NSCodec codec ID. A malicious RDP server can crash a FreeRDP client by sending a crafted Surface Bits …

▾ Sunlitfreerdp · freerdpEPSS 0.38%via NVD
CVE-2026-91959Medium· 6.5PoC
1w ago

FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transport parser

FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transport parser. Attackers can send a malicious BIND_ACK PDU with a truncated result entry to trigger an out-of-bound…

▾ Twilightfreerdp · freerdpEPSS 0.38%via NVD
CVE-2026-91957Low· 3.1
1w ago

FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration

FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration. Attackers can trigger thread creation failure during channel setup to cause …

▾ Sunlitfreerdp · freerdpEPSS 0.36%via NVD
CVE-2026-91963Medium· 6.5PoC⚖ disputed
1w ago

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client…

▾ Twilightfreerdp · freerdpEPSS 0.60%via NVD
CVE-2026-91961Medium· 6.5
1w ago

FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails to validate OutputBufferSize before forwarding to the libusb backend

FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails to validate OutputBufferSize before forwarding to the libusb backend. A malicious RDP server can send a control-trans…

▾ Sunlitfreerdp · freerdpEPSS 0.37%via NVD
CVE-2026-91960Medium· 6.5PoC
1w ago

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service

FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a cra…

▾ Twilightfreerdp · freerdpEPSS 0.46%via NVD
CVE-2026-91964High· 8.8
1w ago

FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields

FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server can trigger the …

▾ TwilightFreeRDP · FreeRDPEPSS 0.60%via NVD
CVE-2026-91962Medium· 6.3
1w ago

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer s…

▾ Sunlitfreerdp · freerdpEPSS 0.26%via NVD
CVE-2026-91986Medium· 5.4PoC
1w ago

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof …

▾ TwilightGitoxideLabs · gitoxideEPSS 0.26%via NVD
CVE-2026-91990High· 7.5PoC
1w ago

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create lar…

▾ Midnighttornadoweb · tornadoEPSS 0.49%via NVD
CVE-2026-91992Medium· 5.9PoC
1w ago

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through th…

▾ Twilighttornadoweb · tornadoEPSS 0.26%via NVD
CVE-2026-91991Medium· 5.4PoC
1w ago

Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie

Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-de…

▾ Twilighttornadoweb · tornadoEPSS 0.28%via NVD
CVE-2026-90439Medium· 6.5
1w ago

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a…

▾ SunlitF5 · NGINX PlusEPSS 0.43%via NVD
CVE-2026-39919Critical· 9.8⚖ disputed
1w ago

Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 imag…

Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 imag…

▾ MidnightArtifex Software · GhostscriptEPSS 0.55%via NVD
CVE-2026-92079Critical· 9.1⚖ disputed
1w ago

Mitigation bypass in the Widget: Win32 component

Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ MidnightMozilla · FirefoxEPSS 0.50%via NVD
CVE-2026-92078Medium· 6.5⚖ disputed
1w ago

Denial-of-service in the Security component

Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ SunlitMozilla · FirefoxEPSS 0.42%via NVD
CVE-2026-92077Medium· 6.5⚖ disputed
1w ago

Denial-of-service in the SVG component

Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ SunlitMozilla · FirefoxEPSS 0.42%via NVD
CVE-2026-92076High· 8.8⚖ disputed
1w ago

Incorrect boundary conditions in the Networking component

Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.16%via NVD
CVE-2026-92075Critical· 9.1⚖ disputed
1w ago

Mitigation bypass in the Networking component

Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ MidnightMozilla · FirefoxEPSS 0.50%via NVD
CVE-2026-92074High· 8.8⚖ disputed
1w ago

Mitigation bypass in the Popup Blocker component

Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.17%via NVD
CVE-2026-92006High· 8.8
1w ago

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16…

▾ TwilightMozilla · FirefoxEPSS 0.35%via NVD
CVE-2026-92015High· 8.8
1w ago

Privilege escalation in the WebExtensions component

Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.28%via NVD
CVEs tagged “csaf” — page 22 · VulnSea