Freerdp

Freerdp

239 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.34%
  • Veröffentlicht 01.08.2026 12:22:18
  • Zuletzt bearbeitet 03.09.2026 19:33:22

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte se...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 01.08.2026 12:22:18
  • Zuletzt bearbeitet 11.09.2026 21:02:51

FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). The client's Pong reply reuses a fixed 1024-byte response stream whose length is not sealed to the actual ...

  • EPSS 0.25%
  • Veröffentlicht 01.08.2026 12:22:18
  • Zuletzt bearbeitet 31.08.2026 20:25:28

FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths outside the configured shared root. A malicious RDP server can read, write, delete, and enumerate fil...

  • EPSS 0.38%
  • Veröffentlicht 01.08.2026 12:22:18
  • Zuletzt bearbeitet 31.08.2026 20:25:28

FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). When processing a RAIL PDU header, the code subtracts RAIL_PDU_HEADER_LENG...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 01.08.2026 12:22:18
  • Zuletzt bearbeitet 08.09.2026 14:32:44

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a fre...

  • EPSS 0.33%
  • Veröffentlicht 01.08.2026 12:22:18
  • Zuletzt bearbeitet 31.08.2026 20:25:28

FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. When a malicious or compromised RDP server sends cra...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 01.08.2026 12:22:18
  • Zuletzt bearbeitet 08.09.2026 14:19:27

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a divide-by-zero vulnerability in the rdpecam camera redirection client. ecam_dev_process_start_streams_request() parses a server-controlled CAM_MEDIA_TYPE_DESCRIPTION from a StartStreamsRe...

  • EPSS 0.25%
  • Veröffentlicht 01.08.2026 12:22:18
  • Zuletzt bearbeitet 29.09.2026 16:17:16

FreeRDP before 3.29.0 contains a reachable assertion (WINPR_ASSERT(OutputBufferLength == BytesReturned)) in serial_process_irp_device_control() in channels/serial/client/serial_main.c. When serial device redirection is enabled and a server-controlled...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 01.08.2026 12:22:18
  • Zuletzt bearbeitet 08.09.2026 14:00:06

FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder functions planar_decompress_plane_rle and planar_decompress_plane_rle_only in libfreerdp/codec/planar.c. Only the 1-byte control byt...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 01.08.2026 12:22:17
  • Zuletzt bearbeitet 02.10.2026 19:08:13

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name and DN...