Freerdp

Freerdp

239 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.45%
  • Veröffentlicht 19.01.2026 17:09:55
  • Zuletzt bearbeitet 15.07.2026 02:18:42

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the ClearCodec bands decode path when crafted band coordinates allow writes past the end of the destination surface...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 19.01.2026 17:07:18
  • Zuletzt bearbeitet 15.07.2026 02:18:42

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the RDPGFX ClearCodec decode path when maliciously crafted residual data causes out-of-bounds writes during color o...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 19.01.2026 17:03:51
  • Zuletzt bearbeitet 15.07.2026 02:18:42

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the FreeRDP client’s `gdi_SurfaceToSurface` path due to a mismatch between destination rectangle clamping and the ...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 19.01.2026 17:01:01
  • Zuletzt bearbeitet 15.07.2026 02:18:41

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, in ClearCodec, when `glyphData` is present, `clear_decompress` calls `freerdp_image_copy_no_overlap` without validating the destination rectangle, allowing an o...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 19.01.2026 16:58:46
  • Zuletzt bearbeitet 15.07.2026 02:18:41

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0,`freerdp_bitmap_decompress_planar` does not validate `nSrcWidth`/`nSrcHeight` against `planar->maxWidth`/`maxHeight` before RLE decode. A malicious server can tr...

Exploit
  • EPSS 0.77%
  • Veröffentlicht 14.01.2026 17:57:37
  • Zuletzt bearbeitet 15.07.2026 02:18:38

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bounds checking on server‑supplied MSUSB_INTERFACE_DESCRIPTOR values and uses them as indices in libusb_udev_complete_msconfig_setup,...

Exploit
  • EPSS 0.61%
  • Veröffentlicht 14.01.2026 17:56:29
  • Zuletzt bearbeitet 15.07.2026 02:18:38

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding path. The root cause appears to be implementation-defined char signedness: on Arm/AArch64 builds, plain...

Exploit
  • EPSS 0.46%
  • Veröffentlicht 14.01.2026 17:53:54
  • Zuletzt bearbeitet 20.01.2026 18:34:43

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_thread_func because the IRP is freed by irp->Complete() and then accessed again on the error path. This vulnerability is fixed in 3....

Exploit
  • EPSS 0.29%
  • Veröffentlicht 14.01.2026 17:53:04
  • Zuletzt bearbeitet 20.01.2026 18:35:44

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP thread tracking allows a heap use‑after‑free when one thread removes an entry from serial->IrpThreads while another reads it. This vuln...

Exploit
  • EPSS 0.77%
  • Veröffentlicht 14.01.2026 17:50:06
  • Zuletzt bearbeitet 15.07.2026 02:18:38

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap out-of-bounds read occurs in the smartcard SetAttrib path when cbAttrLen does not match the actual NDR buffer length. This vulnerability is fixed in 3.20.1.