CVE-2026-25954
- EPSS 0.49%
- Veröffentlicht 25.02.2026 20:30:32
- Zuletzt bearbeitet 27.02.2026 14:56:16
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_rail_server_local_move_size` dereferences a freed `xfAppWindow` pointer because `xf_rail_get_window` returns an unprotected pointer from the `railWindows` h...
CVE-2026-25953
- EPSS 0.59%
- Veröffentlicht 25.02.2026 20:27:00
- Zuletzt bearbeitet 27.02.2026 14:55:56
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reads from a freed `xfAppWindow` because the RDPGFX DVC thread obtains a bare pointer via `xf_rail_get_window` without any lifet...
CVE-2026-25952
- EPSS 0.6%
- Veröffentlicht 25.02.2026 20:24:07
- Zuletzt bearbeitet 27.02.2026 14:55:25
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWindowMinMaxInfo` dereferences a freed `xfAppWindow` pointer because `xf_rail_get_window` in `xf_rail_server_min_max_info` returns an unprotected pointer...
CVE-2026-25941
- EPSS 0.28%
- Veröffentlicht 25.02.2026 20:23:48
- Zuletzt bearbeitet 27.02.2026 14:53:29
FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 have an out-of-bounds read vulnerability in the FreeRDP client's RDPGFX channel that allows a malicio...
CVE-2026-25942
- EPSS 0.45%
- Veröffentlicht 25.02.2026 20:01:16
- Zuletzt bearbeitet 27.02.2026 14:54:06
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_rail_server_execute_result` indexes the global `error_code_names[]` array (7 elements, indices 0–6) with an unchecked `execResult->execResult` value receive...
CVE-2026-24684
- EPSS 0.53%
- Veröffentlicht 09.02.2026 18:23:02
- Zuletzt bearbeitet 10.02.2026 15:02:32
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can process queued PDUs after the channel is closed and internal state is freed, leading to a use after free in rdpsnd_treat_wave. This...
CVE-2026-24683
- EPSS 0.47%
- Veröffentlicht 09.02.2026 18:22:17
- Zuletzt bearbeitet 10.02.2026 15:03:23
FreeRDP is a free implementation of the Remote Desktop Protocol. ainput_send_input_event caches channel_callback in a local variable and later uses it without synchronization; a concurrent channel close can free or reinitialize the callback, leading ...
CVE-2026-24682
- EPSS 0.47%
- Veröffentlicht 09.02.2026 18:21:39
- Zuletzt bearbeitet 10.02.2026 15:04:10
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, audin_server_recv_formats frees an incorrect number of audio formats on parse failure (i + i), leading to out-of-bounds access in audio_formats_free. This vulnerability...
CVE-2026-24681
- EPSS 0.47%
- Veröffentlicht 09.02.2026 18:20:39
- Zuletzt bearbeitet 10.02.2026 15:06:04
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, aAsynchronous bulk transfer completions can use a freed channel callback after URBDRC channel close, leading to a use after free in urb_write_completion. This vulnerabi...
CVE-2026-24680
- EPSS 0.42%
- Veröffentlicht 09.02.2026 18:19:45
- Zuletzt bearbeitet 10.02.2026 15:06:48
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, sdl_Pointer_New frees data on failure, then pointer_free calls sdl_Pointer_Free and frees it again, triggering ASan UAF. This vulnerability is fixed in 3.22.0.