Freerdp

Freerdp

239 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.85%
  • Veröffentlicht 20.07.2026 12:19:46
  • Zuletzt bearbeitet 28.07.2026 15:38:19

FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output buffer via BN_bn2bin() and only afterw...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 20.07.2026 12:19:46
  • Zuletzt bearbeitet 28.07.2026 15:34:52

FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the selectedmonitors field of a .rdp connection file. The MonitorIds array is ...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 10.07.2026 19:52:25
  • Zuletzt bearbeitet 15.07.2026 05:17:19

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in libfreerdp/core/orders.c when multiplying an attacker-controlled point count...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 10.07.2026 19:51:00
  • Zuletzt bearbeitet 13.07.2026 22:44:25

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, FreeRDP server implementations with the MS-RDPECAM camera device enumerator channel enabled scan attacker-supplied DeviceName and VirtualChannelName fields for a NUL te...

Exploit
  • EPSS 0.46%
  • Veröffentlicht 10.07.2026 19:49:03
  • Zuletzt bearbeitet 14.07.2026 15:17:05

FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix for CVE-2026-23530 in planar_decompress_plane_rle_only in libfreerdp/codec/planar.c, allowing...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 10.07.2026 19:47:03
  • Zuletzt bearbeitet 15.07.2026 05:17:15

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.1, FreeRDP clients launched with the non-default /cache:codec:rfx option pass desktop stride and height to RemoteFX decoding for Cache Bitmap V3 data while allocating bitm...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 08.07.2026 13:49:01
  • Zuletzt bearbeitet 10.07.2026 14:36:57

FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to improper synchronization of channel_callback access. A malicious RDP server can trigger a race condition by sending DYNVC_DATA and...

Exploit
  • EPSS 0.63%
  • Veröffentlicht 29.05.2026 19:44:12
  • Zuletzt bearbeitet 29.07.2026 13:18:47

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c, freerdp_bitmap_decompress_planar() validate...

Exploit
  • EPSS 3.67%
  • Veröffentlicht 29.05.2026 19:42:23
  • Zuletzt bearbeitet 27.07.2026 13:18:06

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too-small capa...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 29.05.2026 19:41:46
  • Zuletzt bearbeitet 27.07.2026 13:18:07

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR type or owner...