Freerdp

Freerdp

167 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.04%
  • Veröffentlicht 24.04.2026 02:24:50
  • Zuletzt bearbeitet 27.04.2026 17:44:02

FreeRDP is a free implementation of the Remote Desktop Protocol. Versions prior to 3.25.0 have an off-by-one in the path traversal filter in `channels/drive/client/drive_file.c`. The `contains_dotdot()` function catches `../` and `..\` mid-path but m...

  • EPSS 0.1%
  • Veröffentlicht 30.03.2026 21:43:49
  • Zuletzt bearbeitet 01.04.2026 18:35:09

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a double-free vulnerability in kerberos_AcceptSecurityContext() and kerberos_InitializeSecurityContextA() (WinPR, winpr/libwinpr/sspi/Kerberos/kerberos.c) can c...

  • EPSS 0.02%
  • Veröffentlicht 30.03.2026 21:43:39
  • Zuletzt bearbeitet 01.04.2026 18:44:43

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in persistent_cache_read_entry_v3() in libfreerdp/cache/persistent.c, persistent->bmpSize is updated before winpr_aligned_recalloc(). If realloc fails, bmpSize ...

  • EPSS 0.05%
  • Veröffentlicht 30.03.2026 21:43:21
  • Zuletzt bearbeitet 01.04.2026 19:48:32

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in yuv_ensure_buffer() in libfreerdp/codec/h264.c, h264->width and h264->height are updated before the reallocation loop. If any winpr_aligned_recalloc() call f...

  • EPSS 0.05%
  • Veröffentlicht 30.03.2026 21:43:13
  • Zuletzt bearbeitet 01.04.2026 20:01:13

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap memory is rendered to screen, potentially leaking sensitive data to the attacker. This issue has been patched in version 3.24.2.

  • EPSS 0.05%
  • Veröffentlicht 30.03.2026 21:42:57
  • Zuletzt bearbeitet 01.04.2026 20:02:05

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, s...

  • EPSS 0.05%
  • Veröffentlicht 30.03.2026 21:42:27
  • Zuletzt bearbeitet 01.04.2026 20:03:24

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, progressive_decompress_tile_upgrade() detects a mismatch via progressive_rfx_quant_cmp_equal() but only emits WLog_WARN, execution continues. The wrapped value ...

  • EPSS 0.03%
  • Veröffentlicht 30.03.2026 21:42:11
  • Zuletzt bearbeitet 01.04.2026 20:04:25

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflow READ vulnerability at 24 bytes before the allocation, in winpr_aligned_offset_recalloc(). This issue has been patched in version...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 30.03.2026 21:42:00
  • Zuletzt bearbeitet 02.04.2026 15:16:40

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, an unvalidated auth_length field read from the network triggers a WINPR_ASSERT() failure in rts_read_auth_verifier_no_checks(), causing any FreeRDP client conne...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 30.03.2026 21:41:36
  • Zuletzt bearbeitet 01.04.2026 20:05:49

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a malicious RDP server can crash the FreeRDP client by sending audio data in IMA ADPCM format with an invalid initial step index value (>= 89). The unvalidated ...