CVE-2026-91955
FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attack
CVSS
7.5
High
EPSS
0.5%
p38
KEV
—
Exploit Today
12
0-100
Published: Sep 15, 2026 · Last modified: Sep 16, 2026 · CWE-369
0.5%EPSS · 30 days0.5%
2026-09-162026-09-17
FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server. Attackers can send crafted RDP packets with zero or oversized dimensions to trigger division-by-zero or assertion failures in multifragment update capability calculations, terminating the server process.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-15417—2.6%
——1In the silabser.sys Windows 8 driver for CP210x devices, a local unprivileged user can use incorrect driver settings to cause a kernel crash.8dCVE-2026-795136.5 MED11.2%
——3A divide-by-zero vulnerability in the gf_dash_get_timeline_duration function (src/media_tools/dash_client.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via a crafted MPD SegmentTimeline. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640.3dCVE-2026-62445.5 MED0.9%
——0libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero.10dCVE-2026-85458—0.9%
——0Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height.10dCVE-2026-383456.5 MED16.0%
——5A Division-by-Zero vulnerability in the ff_sws_init_single_context function (/libswscale/utils.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via a crafted input.10dCVE-2026-754666.5 MED10.0%
——3libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexed-color PNG image with a non-gray palette through tj3LoadImage12() or tj3LoadImage16() using the default pixel format, the application may trigger a division-by-zero in alloc_sarray(), causing a SIGFPE and denial of service.9d