CVE-2023-39354
- EPSS 0.19%
- Veröffentlicht 31.08.2023 20:15:08
- Zuletzt bearbeitet 03.11.2025 21:15:58
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Read in the `nsc_rle_decompress_data` function. The Out-Of-Bounds Read occurs because it proce...
CVE-2023-39355
- EPSS 0.28%
- Veröffentlicht 31.08.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 08:15:13
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Versions of FreeRDP on the 3.x release branch before beta3 are subject to a Use-After-Free in processing `RDPGFX_CMDID_RESETGRAPHICS` packets. I...
CVE-2023-40589
- EPSS 0.15%
- Veröffentlicht 31.08.2023 19:15:11
- Zuletzt bearbeitet 03.11.2025 21:16:01
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions there is a Global-Buffer-Overflow in the ncrush_decompress function. Feeding crafted input into this function can trigger t...
CVE-2022-39317
- EPSS 0.08%
- Veröffentlicht 16.11.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:18:01
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing a range check for input offset index in ZGFX decoder. A malicious server can trick a FreeRDP based client to read out of bound data and try to dec...
CVE-2022-39318
- EPSS 0.16%
- Veröffentlicht 16.11.2022 21:15:10
- Zuletzt bearbeitet 03.11.2025 21:15:53
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input validation in `urbdrc` channel. A malicious server can trick a FreeRDP based client to crash with division by zero. This issue has been addr...
CVE-2022-39319
- EPSS 0.11%
- Veröffentlicht 16.11.2022 21:15:10
- Zuletzt bearbeitet 03.11.2025 21:15:53
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length validation in the `urbdrc` channel. A malicious server can trick a FreeRDP based client to read out of bound data and send it back to...
CVE-2022-39316
- EPSS 0.16%
- Veröffentlicht 16.11.2022 20:15:10
- Zuletzt bearbeitet 03.11.2025 21:15:52
FreeRDP is a free remote desktop protocol library and clients. In affected versions there is an out of bound read in ZGFX decoder component of FreeRDP. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it...
CVE-2022-39320
- EPSS 0.07%
- Veröffentlicht 16.11.2022 20:15:10
- Zuletzt bearbeitet 03.11.2025 21:15:53
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP may attempt integer addition on too narrow types leads to allocation of a buffer too small holding the data written. A malicious server can trick a FreeRDP ba...
CVE-2022-39347
- EPSS 0.17%
- Veröffentlicht 16.11.2022 20:15:10
- Zuletzt bearbeitet 03.11.2025 21:15:53
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for `drive` channel. A malicious server can trick a FreeRDP based client to read files outside the share...
CVE-2022-41877
- EPSS 0.12%
- Veröffentlicht 16.11.2022 20:15:10
- Zuletzt bearbeitet 03.11.2025 21:15:54
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length validation in `drive` channel. A malicious server can trick a FreeRDP based client to read out of bound data and send it back to the ...