CVE-2026-23532
- EPSS 0.13%
- Veröffentlicht 19.01.2026 17:03:51
- Zuletzt bearbeitet 28.01.2026 18:48:28
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the FreeRDP client’s `gdi_SurfaceToSurface` path due to a mismatch between destination rectangle clamping and the ...
CVE-2026-23531
- EPSS 0.13%
- Veröffentlicht 19.01.2026 17:01:01
- Zuletzt bearbeitet 28.01.2026 18:51:35
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, in ClearCodec, when `glyphData` is present, `clear_decompress` calls `freerdp_image_copy_no_overlap` without validating the destination rectangle, allowing an o...
CVE-2026-23530
- EPSS 0.15%
- Veröffentlicht 19.01.2026 16:58:46
- Zuletzt bearbeitet 28.01.2026 18:53:04
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0,`freerdp_bitmap_decompress_planar` does not validate `nSrcWidth`/`nSrcHeight` against `planar->maxWidth`/`maxHeight` before RLE decode. A malicious server can tr...
CVE-2026-22859
- EPSS 0.09%
- Veröffentlicht 14.01.2026 17:57:37
- Zuletzt bearbeitet 20.01.2026 18:31:47
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bounds checking on server‑supplied MSUSB_INTERFACE_DESCRIPTOR values and uses them as indices in libusb_udev_complete_msconfig_setup,...
CVE-2026-22858
- EPSS 0.09%
- Veröffentlicht 14.01.2026 17:56:29
- Zuletzt bearbeitet 20.01.2026 18:33:32
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding path. The root cause appears to be implementation-defined char signedness: on Arm/AArch64 builds, plain...
CVE-2026-22857
- EPSS 0.09%
- Veröffentlicht 14.01.2026 17:53:54
- Zuletzt bearbeitet 20.01.2026 18:34:43
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_thread_func because the IRP is freed by irp->Complete() and then accessed again on the error path. This vulnerability is fixed in 3....
CVE-2026-22856
- EPSS 0.07%
- Veröffentlicht 14.01.2026 17:53:04
- Zuletzt bearbeitet 20.01.2026 18:35:44
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP thread tracking allows a heap use‑after‑free when one thread removes an entry from serial->IrpThreads while another reads it. This vuln...
CVE-2026-22855
- EPSS 0.09%
- Veröffentlicht 14.01.2026 17:50:06
- Zuletzt bearbeitet 20.01.2026 18:36:35
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap out-of-bounds read occurs in the smartcard SetAttrib path when cbAttrLen does not match the actual NDR buffer length. This vulnerability is fixed in 3.20.1.
CVE-2026-22854
- EPSS 0.09%
- Veröffentlicht 14.01.2026 17:47:49
- Zuletzt bearbeitet 20.01.2026 18:38:29
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap-buffer-overflow occurs in drive read when a server-controlled read length is used to read file data into an IRP output stream buffer without a hard upper bound, ...
CVE-2026-22853
- EPSS 0.09%
- Veröffentlicht 14.01.2026 17:46:50
- Zuletzt bearbeitet 20.01.2026 18:39:31
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated from hints, causing a heap buffer o...