Freerdp

Freerdp

239 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.27%
  • Veröffentlicht 30.03.2026 21:42:00
  • Zuletzt bearbeitet 02.04.2026 15:16:40

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, an unvalidated auth_length field read from the network triggers a WINPR_ASSERT() failure in rts_read_auth_verifier_no_checks(), causing any FreeRDP client conne...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 30.03.2026 21:41:36
  • Zuletzt bearbeitet 01.04.2026 20:05:49

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a malicious RDP server can crash the FreeRDP client by sending audio data in IMA ADPCM format with an invalid initial step index value (>= 89). The unvalidated ...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 13.03.2026 17:42:11
  • Zuletzt bearbeitet 17.03.2026 12:57:00

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in freerdp_bitmap_decompress_planar when SrcSize is 0. The function dereferences *srcp (which points to pSrcData) without first verifying...

Exploit
  • EPSS 0.66%
  • Veröffentlicht 13.03.2026 17:40:19
  • Zuletzt bearbeitet 15.07.2026 02:19:50

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes SURFACE_BITS_COMMAND messages sent by the RDP server. When the command is handled using NSCodec, the bmp.width and bmp.height...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 13.03.2026 17:38:23
  • Zuletzt bearbeitet 17.03.2026 12:58:04

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in MS-ADPCM and IMA-ADPCM decoders due to unchecked predictor and step_index values from input data. This vulnerability is fixed in 3.24....

Exploit
  • EPSS 0.3%
  • Veröffentlicht 13.03.2026 17:36:57
  • Zuletzt bearbeitet 17.03.2026 14:25:10

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, division by zero in MS-ADPCM and IMA-ADPCM decoders when nBlockAlign is 0, leading to a crash. In libfreerdp/codec/dsp.c, both ADPCM decoders use size % block_size wher...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 13.03.2026 17:35:17
  • Zuletzt bearbeitet 17.03.2026 14:26:13

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a size_t underflow in the IMA-ADPCM and MS-ADPCM audio decoders leads to heap-buffer-overflow write via the RDPSND audio channel. In libfreerdp/codec/dsp.c, the IMA-ADP...

  • EPSS 0.18%
  • Veröffentlicht 13.03.2026 17:33:10
  • Zuletzt bearbeitet 17.03.2026 14:33:19

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's Core Library This vulnerability is fixed in 3.24.0.

Exploit
  • EPSS 0.31%
  • Veröffentlicht 13.03.2026 17:28:39
  • Zuletzt bearbeitet 17.03.2026 14:43:17

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap out-of-bounds read/write occurs in FreeRDP's bitmap cache subsystem due to an off-by-one boundary check in bitmap_cache_put. A malicious server can s...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 13.03.2026 17:26:58
  • Zuletzt bearbeitet 17.03.2026 14:51:38

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap buffer overflow occurs in the FreeRDP client's AVC420/AVC444 YUV-to-RGB conversion path due to missing horizontal bounds validation of H.264 metabloc...