Freerdp

Freerdp

239 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.39%
  • Veröffentlicht 03.09.2026 01:04:43
  • Zuletzt bearbeitet 09.09.2026 19:12:57

FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/core/info.c (rdp_write_logon_info_v2, rdp_write_logon_info_plain, and rdp_write...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 03.09.2026 01:04:43
  • Zuletzt bearbeitet 09.09.2026 19:22:08

FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to tri...

  • EPSS 0.27%
  • Veröffentlicht 19.08.2026 18:02:01
  • Zuletzt bearbeitet 21.08.2026 18:16:50

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67306. Reason: This candidate is a duplicate of CVE-2026-67306. Notes: All CVE users should reference CVE-2026-67306 instead of this candidate.

Exploit
  • EPSS 0.47%
  • Veröffentlicht 19.08.2026 18:00:52
  • Zuletzt bearbeitet 24.09.2026 15:10:37

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context->common.buffer even though opus_decode writes decoded PCM into the cal...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 19.08.2026 17:59:07
  • Zuletzt bearbeitet 22.09.2026 19:41:48

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning poi...

  • EPSS 0.39%
  • Veröffentlicht 19.08.2026 17:55:39
  • Zuletzt bearbeitet 24.09.2026 15:13:21

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated RDP client can advertise DVI ADPCM with nBlockAlign equal to 8 and nChannels equal to 2 to make the `bs` calculation in rdpsnd_server_select_format in ...

Exploit
  • EPSS 0.52%
  • Veröffentlicht 19.08.2026 17:51:19
  • Zuletzt bearbeitet 22.09.2026 19:45:48

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP H.264 decoder backends can return YUV planes sized from the bitstream without comparing the decoded width and height to the RDPGFX surface dimensions used to va...

Exploit
  • EPSS 0.63%
  • Veröffentlicht 19.08.2026 17:50:30
  • Zuletzt bearbeitet 24.09.2026 15:15:35

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than t...

  • EPSS 0.55%
  • Veröffentlicht 19.08.2026 17:48:51
  • Zuletzt bearbeitet 24.09.2026 15:14:57

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, freerdp_image_copy_from_icon_data in libfreerdp/codec/color.c calculates nWidth multiplied by nHeight multiplied by FreeRDPGetBytesPerPixel(format) in 32-bit arithmetic...

Exploit
  • EPSS 0.63%
  • Veröffentlicht 19.08.2026 17:46:39
  • Zuletzt bearbeitet 29.09.2026 19:01:25

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accept a server-controlled max_xmit_frag value in libfreerdp/core/gateway/rpc_bind.c without bounding it to the 4088-byte ReceiveFragme...