VYPR

Vendor CVEs

Freerdp

All CVEs

205 total · sorted by risk
  • CVE-2026-23948HigFeb 9, 2026
    risk 0.00cvss 7.5epss 0.00

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, a NULL pointer dereference vulnerability in rdp_write_logon_info_v2() allows a malicious RDP server to crash FreeRDP proxy by sending a specially crafted LogonInfoV2 PDU with cbDomain=0 or…

  • CVE-2025-68118CriDec 17, 2025
    risk 0.00cvss 9.1epss 0.00

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.20.0, a vulnerability exists in FreeRDP’s certificate handling code on Windows platforms. The function `freerdp_certificate_data_hash_ uses` the Microsoft-specific `_snprintf` function to…

  • CVE-2024-32662HigApr 23, 2024
    risk 0.00cvss 7.5epss 0.01

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. This occurs when `WCHAR` string is read with twice the size it has and converted to `UTF-8`, `base64` decoded. The string is only…

  • CVE-2024-32661HigApr 23, 2024
    risk 0.00cvss 7.5epss 0.01

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to a possible `NULL` access and crash. Version 3.5.1 contains a patch for the issue. No known workarounds are available.

  • CVE-2024-32660HigApr 23, 2024
    risk 0.00cvss 7.5epss 0.01

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.5.1, a malicious server can crash the FreeRDP client by sending invalid huge allocation size. Version 3.5.1 contains a patch for the issue. No known workarounds are available.

  • CVE-2024-32659CriApr 23, 2024
    risk 0.00cvss 9.8epss 0.01

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read if `((nWidth == 0) and (nHeight == 0))`. Version 3.5.1 contains a patch for the issue. No known workarounds are available.

  • CVE-2024-32658CriApr 23, 2024
    risk 0.00cvss 9.8epss 0.01

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. Version 3.5.1 contains a patch for the issue. No known workarounds are available.

  • CVE-2024-32460HigApr 22, 2024
    risk 0.00cvss 8.1epss 0.02

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based based clients using `/bpp:32` legacy `GDI` drawing path with a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a…

  • CVE-2024-32459CriApr 22, 2024
    risk 0.00cvss 9.8epss 0.04

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients and servers that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. No known workarounds are available.

  • CVE-2024-32458CriApr 22, 2024
    risk 0.00cvss 9.8epss 0.02

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, use `/gfx` or `/rfx` modes (on by…

  • CVE-2024-32041CriApr 22, 2024
    risk 0.00cvss 9.8epss 0.02

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, deactivate `/gfx` (on by default, set…

  • CVE-2024-32040HigApr 22, 2024
    risk 0.00cvss 8.1epss 0.02

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 and have connections to servers using the `NSC` codec are vulnerable to integer underflow. Versions 3.5.0 and 2.11.6 patch the issue. As…

  • CVE-2024-32039CriApr 22, 2024
    risk 0.00cvss 9.8epss 0.02

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients using a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to integer overflow and out-of-bounds write. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, do not use `/gfx`…

  • CVE-2024-22211LowJan 19, 2024
    risk 0.00cvss 3.7epss 0.01

    FreeRDP is a set of free and open source remote desktop protocol library and clients. In affected versions an integer overflow in `freerdp_bitmap_planar_context_reset` leads to heap-buffer overflow. This affects FreeRDP based clients. FreeRDP based server implementations and…

  • CVE-2023-39355HigAug 31, 2023
    risk 0.00cvss 7.0epss 0.01

    FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Versions of FreeRDP on the 3.x release branch before beta3 are subject to a Use-After-Free in processing `RDPGFX_CMDID_RESETGRAPHICS` packets. If `context->maxPlaneSize` is…

  • CVE-2023-39354MedAug 31, 2023
    risk 0.00cvss 5.9epss 0.01

    FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Read in the `nsc_rle_decompress_data` function. The Out-Of-Bounds Read occurs because it processes `context->Planes`…

  • CVE-2023-39350MedAug 31, 2023
    risk 0.00cvss 5.9epss 0.01

    FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. This issue affects Clients only. Integer underflow leading to DOS (e.g. abort due to `WINPR_ASSERT` with default compilation flags). When an insufficient blockLen is…

  • CVE-2023-40589MedAug 31, 2023
    risk 0.00cvss 4.3epss 0.01

    FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions there is a Global-Buffer-Overflow in the ncrush_decompress function. Feeding crafted input into this function can trigger the overflow which has only…

  • CVE-2022-39319MedNov 16, 2022
    risk 0.00cvss 4.6epss 0.01

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length validation in the `urbdrc` channel. A malicious server can trick a FreeRDP based client to read out of bound data and send it back to the server. This issue has…

  • CVE-2022-39318MedNov 16, 2022
    risk 0.00cvss 4.8epss 0.01

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input validation in `urbdrc` channel. A malicious server can trick a FreeRDP based client to crash with division by zero. This issue has been addressed in version 2.9.0. All…

  • CVE-2022-41877MedNov 16, 2022
    risk 0.00cvss 4.6epss 0.01

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length validation in `drive` channel. A malicious server can trick a FreeRDP based client to read out of bound data and send it back to the server. This issue has been…

  • CVE-2022-39347LowNov 16, 2022
    risk 0.00cvss 2.6epss 0.01

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for `drive` channel. A malicious server can trick a FreeRDP based client to read files outside the shared directory. This issue has…

  • CVE-2022-39316MedNov 16, 2022
    risk 0.00cvss 4.8epss 0.01

    FreeRDP is a free remote desktop protocol library and clients. In affected versions there is an out of bound read in ZGFX decoder component of FreeRDP. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it likely resulting in a crash.…

  • CVE-2022-24883HigApr 26, 2022
    risk 0.00cvss 7.4epss 0.02

    FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might be successful for invalid credentials if the server has configured an invalid `SAM` file path. FreeRDP based clients are not…

  • CVE-2022-24882CriApr 26, 2022
    risk 0.00cvss 9.1epss 0.03

    FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value. This issue affects FreeRDP based RDP Server implementations. RDP…

  • CVE-2021-37595CriJul 30, 2021
    risk 0.00cvss 9.8epss 0.02

    In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENTS_RANGE File Contents Request PDU.

  • CVE-2021-37594CriJul 30, 2021
    risk 0.00cvss 9.8epss 0.01

    In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENTS_SIZE File Contents Request PDU.

  • CVE-2020-15103LowJul 27, 2020
    risk 0.00cvss 3.5epss 0.01

    In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation in rdpegfx channel. All FreeRDP clients are affected. The input rectangles from the server are not checked against local surface coordinates and blindly accepted. A malicious…

  • CVE-2020-4030LowJun 22, 2020
    risk 0.00cvss 3.5epss 0.02

    In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2.

  • CVE-2020-11099LowJun 22, 2020
    risk 0.00cvss 3.5epss 0.02

    In FreeRDP before version 2.1.2, there is an out of bounds read in license_read_new_or_upgrade_license_packet. A manipulated license packet can lead to out of bound reads to an internal buffer. This is fixed in version 2.1.2.

  • CVE-2020-11098LowJun 22, 2020
    risk 0.00cvss 3.5epss 0.02

    In FreeRDP before version 2.1.2, there is an out-of-bound read in glyph_cache_put. This affects all FreeRDP clients with `+glyph-cache` option enabled This is fixed in version 2.1.2.

  • CVE-2020-11097LowJun 22, 2020
    risk 0.00cvss 3.5epss 0.01

    In FreeRDP before version 2.1.2, an out of bounds read occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.

  • CVE-2020-11096LowJun 22, 2020
    risk 0.00cvss 3.5epss 0.02

    In FreeRDP before version 2.1.2, there is a global OOB read in update_read_cache_bitmap_v3_order. As a workaround, one can disable bitmap cache with -bitmap-cache (default). This is fixed in version 2.1.2.

  • CVE-2020-11095LowJun 22, 2020
    risk 0.00cvss 3.5epss 0.01

    In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.

  • CVE-2020-11089LowMay 29, 2020
    risk 0.00cvss 3.7epss 0.01

    In FreeRDP before 2.1.0, there is an out-of-bound read in irp functions (parallel_process_irp_create, serial_process_irp_create, drive_process_irp_write, printer_process_irp_write, rdpei_recv_pdu, serial_process_irp_write). This has been fixed in 2.1.0.

  • CVE-2020-11088LowMay 29, 2020
    risk 0.00cvss 3.1epss 0.01

    In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_NegotiateMessage. This has been fixed in 2.1.0.

  • CVE-2020-11087LowMay 29, 2020
    risk 0.00cvss 3.1epss 0.01

    In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_AuthenticateMessage. This has been fixed in 2.1.0.

  • CVE-2020-11086LowMay 29, 2020
    risk 0.00cvss 3.1epss 0.01

    In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_ntlm_v2_client_challenge that reads up to 28 bytes out-of-bound to an internal structure. This has been fixed in 2.1.0.

  • CVE-2020-11085LowMay 29, 2020
    risk 0.00cvss 2.6epss 0.02

    In FreeRDP before 2.1.0, there is an out-of-bounds read in cliprdr_read_format_list. Clipboard format data read (by client or server) might read data out-of-bounds. This has been fixed in 2.1.0.

  • CVE-2020-13398HigMay 22, 2020
    risk 0.00cvss 8.3epss 0.02

    An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.

  • CVE-2020-13397MedMay 22, 2020
    risk 0.00cvss 5.5epss 0.01

    An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in security_fips_decrypt in libfreerdp/core/security.c due to an uninitialized value.

  • CVE-2020-13396HigMay 22, 2020
    risk 0.00cvss 7.1epss 0.02

    An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.

  • CVE-2020-11525LowMay 15, 2020
    risk 0.00cvss 2.2epss 0.02

    libfreerdp/cache/bitmap.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out of bounds read.

  • CVE-2020-11058LowMay 12, 2020
    risk 0.00cvss 2.2epss 0.02

    In FreeRDP after 1.1 and before 2.0.0, a stream out-of-bounds seek in rdp_read_font_capability_set could lead to a later out-of-bounds read. As a result, a manipulated client or server might force a disconnect due to an invalid data read. This has been fixed in 2.0.0.

  • CVE-2020-11049MedMay 7, 2020
    risk 0.00cvss 5.5epss 0.02

    In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bound read of client memory that is then passed on to the protocol parser. This has been patched in 2.0.0.

  • CVE-2020-11048LowMay 7, 2020
    risk 0.00cvss 2.2epss 0.02

    In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bounds read. It only allows to abort a session. No data extraction is possible. This has been fixed in 2.0.0.

  • CVE-2020-11047MedMay 7, 2020
    risk 0.00cvss 5.5epss 0.02

    In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A malicious server can extract up to 8 bytes of client memory with a manipulated message by providing a short input and reading the measurement result data. This…

  • CVE-2020-11046MedMay 7, 2020
    risk 0.00cvss 5.5epss 0.01

    In FreeRDP after 1.0 and before 2.0.0, there is a stream out-of-bounds seek in update_read_synchronize that could lead to a later out-of-bounds read.

  • CVE-2020-11045LowMay 7, 2020
    risk 0.00cvss 2.2epss 0.02

    In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bound read in in update_read_bitmap_data that allows client memory to be read to an image buffer. The result displayed on screen as colour.

  • CVE-2020-11044LowMay 7, 2020
    risk 0.00cvss 2.2epss 0.02

    In FreeRDP greater than 1.2 and before 2.0.0, a double free in update_read_cache_bitmap_v3_order crashes the client application if corrupted data from a manipulated server is parsed. This has been patched in 2.0.0.

Page 4 of 5