Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server. Attackers can send crafted RDP packets with zero or oversized dimensions to trigger division-by-zero or assertion failures in multifragment update capability calculations, terminating the server process. | |
| Title | FreeRDP before 3.31.0 Denial of Service via Desktop Dimensions | |
| First Time appeared |
Freerdp
Freerdp freerdp |
|
| Weaknesses | CWE-369 | |
| CPEs | cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Freerdp
Freerdp freerdp |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T15:54:42.025Z
Reserved: 2026-09-15T11:07:34.398Z
Link: CVE-2026-91955
Updated: 2026-09-15T15:54:38.299Z
Status : Received
Published: 2026-09-15T16:17:49.963
Modified: 2026-09-15T16:17:49.963
Link: CVE-2026-91955
No data.
OpenCVE Enrichment
No data.
-
CWE-369
Divide By Zero