Freerdp

Freerdp

157 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.11%
  • Veröffentlicht 25.02.2026 20:24:07
  • Zuletzt bearbeitet 27.02.2026 14:55:25

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWindowMinMaxInfo` dereferences a freed `xfAppWindow` pointer because `xf_rail_get_window` in `xf_rail_server_min_max_info` returns an unprotected pointer...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 25.02.2026 20:23:48
  • Zuletzt bearbeitet 27.02.2026 14:53:29

FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 have an out-of-bounds read vulnerability in the FreeRDP client's RDPGFX channel that allows a malicio...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 25.02.2026 20:01:16
  • Zuletzt bearbeitet 27.02.2026 14:54:06

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_rail_server_execute_result` indexes the global `error_code_names[]` array (7 elements, indices 0–6) with an unchecked `execResult->execResult` value receive...

  • EPSS 0.02%
  • Veröffentlicht 09.02.2026 18:23:02
  • Zuletzt bearbeitet 10.02.2026 15:02:32

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can process queued PDUs after the channel is closed and internal state is freed, leading to a use after free in rdpsnd_treat_wave. This...

  • EPSS 0.02%
  • Veröffentlicht 09.02.2026 18:22:17
  • Zuletzt bearbeitet 10.02.2026 15:03:23

FreeRDP is a free implementation of the Remote Desktop Protocol. ainput_send_input_event caches channel_callback in a local variable and later uses it without synchronization; a concurrent channel close can free or reinitialize the callback, leading ...

  • EPSS 0.02%
  • Veröffentlicht 09.02.2026 18:21:39
  • Zuletzt bearbeitet 10.02.2026 15:04:10

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, audin_server_recv_formats frees an incorrect number of audio formats on parse failure (i + i), leading to out-of-bounds access in audio_formats_free. This vulnerability...

  • EPSS 0.02%
  • Veröffentlicht 09.02.2026 18:20:39
  • Zuletzt bearbeitet 10.02.2026 15:06:04

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, aAsynchronous bulk transfer completions can use a freed channel callback after URBDRC channel close, leading to a use after free in urb_write_completion. This vulnerabi...

  • EPSS 0.02%
  • Veröffentlicht 09.02.2026 18:19:45
  • Zuletzt bearbeitet 10.02.2026 15:06:48

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, sdl_Pointer_New frees data on failure, then pointer_free calls sdl_Pointer_Free and frees it again, triggering ASan UAF. This vulnerability is fixed in 3.22.0.

  • EPSS 0.02%
  • Veröffentlicht 09.02.2026 18:19:00
  • Zuletzt bearbeitet 10.02.2026 15:08:26

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, The URBDRC client uses server-supplied interface numbers as array indices without bounds checks, causing an out-of-bounds read in libusb_udev_select_interface. This vul...

  • EPSS 0.02%
  • Veröffentlicht 09.02.2026 18:17:27
  • Zuletzt bearbeitet 10.02.2026 15:08:47

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample responses using a freed channel callback after a device channel close, leading to a use after free in ecam_channel_write. This vulnerabili...