CVE-2026-23534
- EPSS 0.45%
- Veröffentlicht 19.01.2026 17:09:55
- Zuletzt bearbeitet 15.07.2026 02:18:42
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the ClearCodec bands decode path when crafted band coordinates allow writes past the end of the destination surface...
CVE-2026-23533
- EPSS 0.45%
- Veröffentlicht 19.01.2026 17:07:18
- Zuletzt bearbeitet 15.07.2026 02:18:42
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the RDPGFX ClearCodec decode path when maliciously crafted residual data causes out-of-bounds writes during color o...
CVE-2026-23532
- EPSS 0.45%
- Veröffentlicht 19.01.2026 17:03:51
- Zuletzt bearbeitet 15.07.2026 02:18:42
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the FreeRDP client’s `gdi_SurfaceToSurface` path due to a mismatch between destination rectangle clamping and the ...
CVE-2026-23531
- EPSS 0.45%
- Veröffentlicht 19.01.2026 17:01:01
- Zuletzt bearbeitet 15.07.2026 02:18:41
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, in ClearCodec, when `glyphData` is present, `clear_decompress` calls `freerdp_image_copy_no_overlap` without validating the destination rectangle, allowing an o...
CVE-2026-23530
- EPSS 0.45%
- Veröffentlicht 19.01.2026 16:58:46
- Zuletzt bearbeitet 15.07.2026 02:18:41
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0,`freerdp_bitmap_decompress_planar` does not validate `nSrcWidth`/`nSrcHeight` against `planar->maxWidth`/`maxHeight` before RLE decode. A malicious server can tr...
CVE-2026-22859
- EPSS 0.77%
- Veröffentlicht 14.01.2026 17:57:37
- Zuletzt bearbeitet 15.07.2026 02:18:38
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bounds checking on server‑supplied MSUSB_INTERFACE_DESCRIPTOR values and uses them as indices in libusb_udev_complete_msconfig_setup,...
CVE-2026-22858
- EPSS 0.61%
- Veröffentlicht 14.01.2026 17:56:29
- Zuletzt bearbeitet 15.07.2026 02:18:38
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding path. The root cause appears to be implementation-defined char signedness: on Arm/AArch64 builds, plain...
CVE-2026-22857
- EPSS 0.46%
- Veröffentlicht 14.01.2026 17:53:54
- Zuletzt bearbeitet 20.01.2026 18:34:43
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_thread_func because the IRP is freed by irp->Complete() and then accessed again on the error path. This vulnerability is fixed in 3....
CVE-2026-22856
- EPSS 0.29%
- Veröffentlicht 14.01.2026 17:53:04
- Zuletzt bearbeitet 20.01.2026 18:35:44
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP thread tracking allows a heap use‑after‑free when one thread removes an entry from serial->IrpThreads while another reads it. This vuln...
CVE-2026-22855
- EPSS 0.77%
- Veröffentlicht 14.01.2026 17:50:06
- Zuletzt bearbeitet 15.07.2026 02:18:38
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap out-of-bounds read occurs in the smartcard SetAttrib path when cbAttrLen does not match the actual NDR buffer length. This vulnerability is fixed in 3.20.1.