CVE-2026-67289
- EPSS 0.38%
- Veröffentlicht 01.08.2026 12:22:17
- Zuletzt bearbeitet 02.10.2026 19:12:56
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects thr...
CVE-2026-67294
- EPSS 0.27%
- Veröffentlicht 01.08.2026 12:22:17
- Zuletzt bearbeitet 11.09.2026 21:03:16
FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side server TLS authentication. In x509_utils_verify(), when server-purpose (X509_PURPOSE_SSL_SERVER) verification fails, the code f...
CVE-2026-67296
- EPSS 0.34%
- Veröffentlicht 01.08.2026 12:22:17
- Zuletzt bearbeitet 11.09.2026 21:03:57
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large dec...
CVE-2026-67304
- EPSS 0.35%
- Veröffentlicht 01.08.2026 12:22:17
- Zuletzt bearbeitet 08.09.2026 14:07:18
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-stat...
CVE-2026-67290
- EPSS 0.43%
- Veröffentlicht 01.08.2026 12:22:16
- Zuletzt bearbeitet 29.09.2026 16:17:35
FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a cras...
CVE-2026-67293
- EPSS 0.17%
- Veröffentlicht 01.08.2026 12:22:16
- Zuletzt bearbeitet 29.09.2026 16:17:25
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. The TLS hostname matcher (tls_match_hostname() in libfreerdp/crypto/tls.c) treats a wildcard pattern such as *.example.com as matc...
CVE-2026-67297
- EPSS 0.34%
- Veröffentlicht 01.08.2026 12:22:16
- Zuletzt bearbeitet 11.09.2026 21:04:27
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to...
CVE-2026-67301
- EPSS 0.34%
- Veröffentlicht 01.08.2026 12:22:16
- Zuletzt bearbeitet 08.09.2026 14:27:34
FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and upd...
CVE-2026-67305
- EPSS 0.49%
- Veröffentlicht 01.08.2026 12:22:16
- Zuletzt bearbeitet 08.09.2026 14:04:42
FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination buffer. A mali...
CVE-2026-64624
- EPSS 0.18%
- Veröffentlicht 20.07.2026 21:50:53
- Zuletzt bearbeitet 29.07.2026 15:21:10
FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive option...