VYPR

Freerdp

by Freerdp

Source repositories

CVEs (237)

  • CVE-2017-2837MedApr 24, 2018
    risk 0.38cvss 5.9epss 0.02

    An exploitable denial of service vulnerability exists within the handling of security data in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet can cause the program termination leading to a denial of service condition. An attacker can compromise the server or…

  • CVE-2017-2836MedApr 24, 2018
    risk 0.38cvss 5.9epss 0.01

    An exploitable denial of service vulnerability exists within the reading of proprietary server certificates in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet can cause the program termination leading to a denial of service condition. An attacker can…

  • CVE-2026-91958MedSep 15, 2026
    risk 0.36cvss 6.6epss 0.00

    FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap…

  • CVE-2022-39320MedNov 16, 2022
    risk 0.36cvss 5.5epss 0.01

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP may attempt integer addition on too narrow types leads to allocation of a buffer too small holding the data written. A malicious server can trick a FreeRDP based client to read out of…

  • CVE-2020-13397MedMay 22, 2020
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in security_fips_decrypt in libfreerdp/core/security.c due to an uninitialized value.

  • CVE-2020-11049MedMay 7, 2020
    risk 0.36cvss 5.5epss 0.02

    In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bound read of client memory that is then passed on to the protocol parser. This has been patched in 2.0.0.

  • CVE-2020-11047MedMay 7, 2020
    risk 0.36cvss 5.5epss 0.02

    In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A malicious server can extract up to 8 bytes of client memory with a manipulated message by providing a short input and reading the measurement result data. This…

  • CVE-2020-11046MedMay 7, 2020
    risk 0.36cvss 5.5epss 0.01

    In FreeRDP after 1.0 and before 2.0.0, there is a stream out-of-bounds seek in update_read_synchronize that could lead to a later out-of-bounds read.

  • CVE-2020-11042MedMay 7, 2020
    risk 0.36cvss 5.5epss 0.02

    In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_info. It allows reading a attacker-defined amount of client memory (32bit unsigned -> 4GB) to an intermediate buffer. This can be used to crash the client or store information for…

  • CVE-2026-91963MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.01

    FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code…

  • CVE-2026-91961MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails to validate OutputBufferSize before forwarding to the libusb backend. A malicious RDP server can send a control-transfer request with OutputBufferSize set to…

  • CVE-2026-91960MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to…

  • CVE-2026-91959MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transport parser. Attackers can send a malicious BIND_ACK PDU with a truncated result entry to trigger an out-of-bounds read causing process abort.

  • CVE-2026-91956MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function that indexes interface arrays by position instead of protocol field InterfaceNumber. A malicious RDP server can send a crafted SELECT_CONFIGURATION message with…

  • CVE-2026-91954MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits commands with NSCodec codec ID. A malicious RDP server can crash a FreeRDP client by sending a crafted Surface Bits command claiming to use NSCodec, even when…

  • CVE-2026-91953MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fails to validate the LB_LOAD_BALANCE_INFO field length before writing to a fixed 512-byte buffer. A malicious RDP server or man-in-the-middle can send a Server…

  • CVE-2026-91952MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the…

  • CVE-2026-91951MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte write past the allocated…

  • CVE-2026-91950MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malicious RDP server can send a crafted RDPDR packet with computerNameLen set to 0xFFFFFFF0 to bypass…

  • CVE-2026-91946MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memory including live pointers…

Page 6 of 12