CVE-2026-22852
- EPSS 0.09%
- Veröffentlicht 14.01.2026 17:45:22
- Zuletzt bearbeitet 20.01.2026 18:40:31
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client when processing Audio Input (AUDIN) format lists. audin_process_formats reuses cal...
CVE-2026-22851
- EPSS 0.06%
- Veröffentlicht 14.01.2026 17:43:28
- Zuletzt bearbeitet 20.01.2026 18:43:31
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race condition between the RDPGFX dynamic virtual channel thread and the SDL render thread leads to a heap use-after-free. Specifically, an escaped pointer to sdl->pr...
CVE-2025-68118
- EPSS 0.05%
- Veröffentlicht 17.12.2025 22:01:14
- Zuletzt bearbeitet 02.01.2026 16:41:23
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.20.0, a vulnerability exists in FreeRDP’s certificate handling code on Windows platforms. The function `freerdp_certificate_data_hash_ uses` the Microsoft-specific `_...
CVE-2025-4478
- EPSS 0.36%
- Veröffentlicht 16.05.2025 14:22:17
- Zuletzt bearbeitet 21.01.2026 14:16:05
A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot ...
CVE-2024-32662
- EPSS 0.33%
- Veröffentlicht 23.04.2024 21:15:48
- Zuletzt bearbeitet 04.02.2025 17:44:06
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. This occurs when `WCHAR` string is read with twice the size it has and converted to `UTF-8`, `base64` ...
CVE-2024-32659
- EPSS 0.41%
- Veröffentlicht 23.04.2024 20:15:07
- Zuletzt bearbeitet 03.11.2025 21:16:10
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read if `((nWidth == 0) and (nHeight == 0))`. Version 3.5.1 contains a patch for the issue. No known workaro...
CVE-2024-32660
- EPSS 0.43%
- Veröffentlicht 23.04.2024 20:15:07
- Zuletzt bearbeitet 03.11.2025 21:16:10
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.5.1, a malicious server can crash the FreeRDP client by sending invalid huge allocation size. Version 3.5.1 contains a patch for the issue. No known workarounds are a...
CVE-2024-32661
- EPSS 0.59%
- Veröffentlicht 23.04.2024 20:15:07
- Zuletzt bearbeitet 03.11.2025 21:16:10
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to a possible `NULL` access and crash. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
CVE-2024-32658
- EPSS 1.77%
- Veröffentlicht 23.04.2024 18:15:15
- Zuletzt bearbeitet 03.11.2025 21:16:10
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
CVE-2024-32459
- EPSS 11.21%
- Veröffentlicht 22.04.2024 22:15:07
- Zuletzt bearbeitet 03.11.2025 21:16:10
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients and servers that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. No known workar...