CVE-2026-64620
- EPSS 0.85%
- Veröffentlicht 20.07.2026 12:19:46
- Zuletzt bearbeitet 28.07.2026 15:38:19
FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output buffer via BN_bn2bin() and only afterw...
CVE-2026-64621
- EPSS 0.3%
- Veröffentlicht 20.07.2026 12:19:46
- Zuletzt bearbeitet 28.07.2026 15:34:52
FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the selectedmonitors field of a .rdp connection file. The MonitorIds array is ...
CVE-2026-57156
- EPSS 0.42%
- Veröffentlicht 10.07.2026 19:52:25
- Zuletzt bearbeitet 15.07.2026 05:17:19
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in libfreerdp/core/orders.c when multiplying an attacker-controlled point count...
CVE-2026-57157
- EPSS 0.37%
- Veröffentlicht 10.07.2026 19:51:00
- Zuletzt bearbeitet 13.07.2026 22:44:25
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, FreeRDP server implementations with the MS-RDPECAM camera device enumerator channel enabled scan attacker-supplied DeviceName and VirtualChannelName fields for a NUL te...
CVE-2026-57158
- EPSS 0.46%
- Veröffentlicht 10.07.2026 19:49:03
- Zuletzt bearbeitet 14.07.2026 15:17:05
FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix for CVE-2026-23530 in planar_decompress_plane_rle_only in libfreerdp/codec/planar.c, allowing...
CVE-2026-55827
- EPSS 0.34%
- Veröffentlicht 10.07.2026 19:47:03
- Zuletzt bearbeitet 15.07.2026 05:17:15
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.1, FreeRDP clients launched with the non-default /cache:codec:rfx option pass desktop stride and height to RemoteFX decoding for Cache Bitmap V3 data while allocating bitm...
CVE-2026-56297
- EPSS 0.36%
- Veröffentlicht 08.07.2026 13:49:01
- Zuletzt bearbeitet 10.07.2026 14:36:57
FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to improper synchronization of channel_callback access. A malicious RDP server can trigger a race condition by sending DYNVC_DATA and...
CVE-2026-45700
- EPSS 0.63%
- Veröffentlicht 29.05.2026 19:44:12
- Zuletzt bearbeitet 29.07.2026 13:18:47
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c, freerdp_bitmap_decompress_planar() validate...
CVE-2026-44420
- EPSS 3.67%
- Veröffentlicht 29.05.2026 19:42:23
- Zuletzt bearbeitet 27.07.2026 13:18:06
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too-small capa...
CVE-2026-44422
- EPSS 0.43%
- Veröffentlicht 29.05.2026 19:41:46
- Zuletzt bearbeitet 27.07.2026 13:18:07
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR type or owner...