VYPR

Freerdp

by Freerdp

Source repositories

CVEs (237)

  • CVE-2026-73242HigAug 11, 2026
    risk 0.47cvss —epss 0.00

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using it with RRC in IOV pointer offsets,…

  • CVE-2026-73241HigAug 11, 2026
    risk 0.47cvss —epss 0.00

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an attacker-supplied RDSTLS_TYPE_CAPABILITIES PDU while rdstls_server_authenticate is waiting for RDSTLS_TYPE_AUTHREQ, leaving…

  • CVE-2017-2834HigApr 24, 2018
    risk 0.46cvss 7.0epss 0.02

    An exploitable code execution vulnerability exists in the authentication functionality of FreeRDP 2.0.0-beta1+android11. A specially crafted server response can cause an out-of-bounds write resulting in an exploitable condition. An attacker can compromise the server or use a man…

  • CVE-2020-11038MedMay 29, 2020
    risk 0.45cvss 6.9epss 0.01

    In FreeRDP less than or equal to 2.0.0, an Integer Overflow to Buffer Overflow exists. When using /video redirection, a manipulated server can instruct the client to allocate a buffer with a smaller size than requested due to an integer overflow in size calculation. With later…

  • CVE-2026-64624HigJul 20, 2026
    risk 0.44cvss 7.8epss 0.00

    FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary…

  • CVE-2026-63633HigAug 19, 2026
    risk 0.43cvss —epss 0.00

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context->common.buffer even though opus_decode writes decoded PCM into the caller-supplied out stream. A…

  • CVE-2020-11524MedMay 15, 2020
    risk 0.43cvss 6.6epss 0.02

    libfreerdp/codec/interleaved.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.

  • CVE-2020-11523MedMay 15, 2020
    risk 0.43cvss 6.6epss 0.02

    libfreerdp/gdi/region.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Integer Overflow.

  • CVE-2020-11521MedMay 15, 2020
    risk 0.43cvss 6.6epss 0.02

    libfreerdp/codec/planar.c in FreeRDP version > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.

  • CVE-2026-91955HigSep 15, 2026
    risk 0.42cvss 7.5epss 0.00

    FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server. Attackers can send crafted RDP packets with zero or oversized dimensions to trigger division-by-zero or assertion…

  • CVE-2026-91948HigSep 15, 2026
    risk 0.42cvss 7.5epss 0.01

    FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory…

  • CVE-2026-91947HigSep 15, 2026
    risk 0.42cvss 7.5epss 0.00

    FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger…

  • CVE-2026-68580HigAug 2, 2026
    risk 0.42cvss 7.5epss 0.00

    FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket…

  • CVE-2026-67304HigAug 1, 2026
    risk 0.42cvss 7.5epss 0.00

    FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-state data to crash the process…

  • CVE-2026-67301HigAug 1, 2026
    risk 0.42cvss 7.5epss 0.00

    FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and update_message_PolygonCB()…

  • CVE-2026-67300HigAug 1, 2026
    risk 0.42cvss 7.5epss 0.00

    FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. When a malicious or compromised RDP server sends crafted update orders, the…

  • CVE-2026-67299HigAug 1, 2026
    risk 0.42cvss 7.5epss 0.00

    FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a freshly allocated…

  • CVE-2026-67298HigAug 1, 2026
    risk 0.42cvss 7.5epss 0.00

    FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). When processing a RAIL PDU header, the code subtracts RAIL_PDU_HEADER_LENGTH from the peer-controlled…

  • CVE-2026-67297HigAug 1, 2026
    risk 0.42cvss 7.5epss 0.00

    FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory…

  • CVE-2026-67296HigAug 1, 2026
    risk 0.42cvss 7.5epss 0.00

    FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force…

Page 3 of 12