freerdp

167 tracked vulnerabilities.

CVE-2026-40254 MEDIUM
FreeRDP: contains_dotdot() off-by-one allows drive channel path traversal via terminal ..
Apr 24, 2026
CVSS 4.2
EPSS 0.00
CVE-2026-33995 MEDIUM
FreeRDP: Possible double free in kerberos_AcceptSecurityContext
Mar 30, 2026
CVSS 5.3
EPSS 0.00
CVE-2026-33987 HIGH
FreeRDP: Persistent Cache bmpSize Desync - Heap OOB Write
Mar 30, 2026
CVSS 7.1
EPSS 0.00
CVE-2026-33986 HIGH
FreeRDP: H.264 YUV Buffer Dimension Desync - Heap OOB Write
Mar 30, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-33985 MEDIUM
FreeRDP: ClearCodec Glyph Cache Count Desync - Heap OOB Read
Mar 30, 2026
CVSS 5.9
EPSS 0.00
CVE-2026-33984 HIGH
FreeRDP: ClearCodec resize_vbar_entry() Heap OOB Write
Mar 30, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-33983 MEDIUM
FreeRDP: Progressive Codec Quant BYTE Underflow - UB + CPU DoS
Mar 30, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-33982 HIGH
FreeRDP: Persistent Cache Allocator Mismatch - Heap OOB Read
Mar 30, 2026
CVSS 7.1
EPSS 0.00
CVE-2026-33977 MEDIUM
FreeRDP: DoS via WINPR_ASSERT in IMA ADPCM audio decoder (dsp.c:331)
Mar 30, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-33952 MEDIUM
FreeRDP: DoS via WINPR_ASSERT in rts_read_auth_verifier_no_checks
Mar 30, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-31897 NONE
FreeRDP <3.24.0 - Out-of-Bounds Read
Mar 13, 2026
EPSS 0.00
CVE-2026-31885 MEDIUM
FreeRDP <3.24.0 - Memory Corruption
Mar 13, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-31884 MEDIUM
FreeRDP < 3.24.0 - Denial of Service via Division by Zero in ADPCM Decoders
Mar 13, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-31883 MEDIUM
FreeRDP <3.24.0 - Heap Buffer Overflow
Mar 13, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-31806 CRITICAL
FreeRDP <3.24.0 - Memory Corruption
Mar 13, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-29776 LOW
FreeRDP <3.24.0 - Memory Corruption
Mar 13, 2026
CVSS 3.1
EPSS 0.00
CVE-2026-29775 MEDIUM
FreeRDP <3.24.0 - Memory Corruption
Mar 13, 2026
CVSS 5.3
EPSS 0.00
CVE-2026-29774 MEDIUM
FreeRDP < 3.24.0 - Heap Buffer Overflow in AVC420 YUV-to-RGB Conversion
Mar 13, 2026
CVSS 5.3
EPSS 0.00
CVE-2026-27951 MEDIUM
FreeRDP < 3.23.0 - Denial of Service via Stream_EnsureCapacity
Feb 25, 2026
CVSS 5.3
EPSS 0.00
CVE-2026-27950 HIGH
FreeRDP < 3.23.0 - Use-After-Free in SDL2 Pointer Implementation
Feb 25, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-26986 HIGH
FreeRDP < 3.23.0 - Use-After-Free in xf_rail_window_common
Feb 25, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-27015 MEDIUM
FreeRDP < 3.23.0 - Denial of Service via Smartcard Read Size Alignment Bounds Check
Feb 25, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-26965 HIGH
FreeRDP <3.23.0 - Memory Corruption
Feb 25, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-26955 HIGH
FreeRDP < 3.23.0 - Heap Buffer Overflow via GDI Surface Command ClearCodec
Feb 25, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-26271 MEDIUM
FreeRDP < 3.23.0 - Buffer Over-read in TS_ICON_INFO Icon Data Processing
Feb 25, 2026
CVSS 5.3
EPSS 0.00