Vulnerability index

Browse CVEs

88 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Freerdp CRITICAL 9.8
CVE-2026-23534

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the ClearCodec…

Fix: 3.21.0+
Fix from $2,300 2026-01-19
Freerdp HIGH 7.5
CVE-2026-23732

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, FastGlyph parsing trusts `cbData`/remaining length and neve…

Fix: 3.21.0+
Fix from $1,950 2026-01-19
Freerdp CRITICAL 9.8
CVE-2026-23532

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the FreeRDP c…

Fix: 3.21.0+
Fix from $2,300 2026-01-19
Freerdp CRITICAL 9.8
CVE-2026-23530

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0,`freerdp_bitmap_decompress_planar` does not validate `nSrcWi…

Fix: 3.21.0+
Fix from $2,300 2026-01-19
Freerdp CRITICAL 9.8
CVE-2026-23531

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, in ClearCodec, when `glyphData` is present, `clear_decompre…

Fix: 3.21.0+
Fix from $2,300 2026-01-19
Freerdp CRITICAL 9.8
CVE-2026-22857

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_thread_func because the IRP is …

Fix: 3.20.1+
Fix from $2,300 2026-01-14
Freerdp CRITICAL 9.1
CVE-2026-22855

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap out-of-bounds read occurs in the smartcard SetAttrib path wh…

Fix: 3.20.1+
Fix from $2,300 2026-01-14
Freerdp CRITICAL 9.1
CVE-2026-22858

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding pa…

Fix: 3.20.1+
Fix from $2,300 2026-01-14
Freerdp CRITICAL 9.1
CVE-2026-22859

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bounds checking on server‑suppli…

Fix: 3.20.1+
Fix from $2,300 2026-01-14
Freerdp HIGH 8.1
CVE-2026-22856

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP thread tracking allows a heap use‑…

Fix: 3.20.1+
Fix from $1,950 2026-01-14
Freerdp CRITICAL 9.8
CVE-2026-22852

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a malicious RDP server can trigger a heap-buffer-overflow write in …

Fix: 3.20.1+
Fix from $2,300 2026-01-14
Freerdp CRITICAL 9.8
CVE-2026-22853

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the o…

Fix: 3.20.1+
Fix from $2,300 2026-01-14
Freerdp CRITICAL 9.8
CVE-2026-22854

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap-buffer-overflow occurs in drive read when a server-controlle…

Fix: 3.20.1+
Fix from $2,300 2026-01-14
Freerdp MEDIUM 5.9
CVE-2026-22851

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race condition between the RDPGFX dynamic virtual channel thread …

Fix: 3.20.1+
Fix from $1,600 2026-01-14
Freerdp CRITICAL 9.1
CVE-2025-68118

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.20.0, a vulnerability exists in FreeRDP’s certificate handling co…

Fix: 3.20.0+
Fix from $2,300 2025-12-17
Freerdp CRITICAL 9.8
CVE-2024-22211

FreeRDP is a set of free and open source remote desktop protocol library and clients. In affected versions an integer overflow in `freerdp_bitmap_pla…

Fix: 2.11.5 / 3.2.0+
Fix from $2,300 2024-01-19
Freerdp CRITICAL 9.8
CVE-2023-40187

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions of the 3.x beta branch ar…

No fix yet
Fix from $2,300 2023-08-31
Freerdp CRITICAL 9.8
CVE-2023-40574

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-…

No fix yet
Fix from $2,300 2023-08-31
Freerdp CRITICAL 9.1
CVE-2023-40575

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-…

No fix yet
Fix from $2,300 2023-08-31
Freerdp HIGH 7.5
CVE-2023-40576

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-…

No fix yet
Fix from $1,950 2023-08-31
Freerdp CRITICAL 9.8
CVE-2021-37594

In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENT…

Fix: 2.4.0+
Fix from $2,300 2021-07-30
Freerdp CRITICAL 9.8
CVE-2021-37595

In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENT…

Fix: 2.4.0+
Fix from $2,300 2021-07-30
Freerdp HIGH 7.5
CVE-2019-17177

libfreerdp/codec/region.c in FreeRDP through 1.1.x and 2.x through 2.0.0-rc4 has memory leaks because a supplied realloc pointer (i.e., the first arg…

Fix: after 1.0.2
Fix from $1,950 2019-10-04
Freerdp HIGH 7.5
CVE-2019-17178

HuffmanTree_makeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in FreeRDP and other products, has a memory leak because…

Fix: after 2019-09-28
Fix from $1,950 2019-10-04
Freerdp HIGH 7.5
CVE-2013-4119

FreeRDP before 1.1.0-beta+2013071101 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by disconn…

Fix: after 1.0.2
Fix from $1,950 2016-10-03
Freerdp HIGH 7.5
CVE-2013-4118

FreeRDP before 1.1.0-beta1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vect…

Fix: after 1.0.2
Fix from $1,950 2016-10-03
Freerdp HIGH 7.5
CVE-2014-0250

Multiple integer overflows in client/X11/xf_graphics.c in FreeRDP allow remote attackers to have an unspecified impact via the width and height to th…

Patch available
Fix from $1,950 2014-11-16
Freerdp MEDIUM 6.8
CVE-2014-0791

Integer overflow in the license_read_scope_list function in libfreerdp/core/license.c in FreeRDP through 1.0.2 allows remote RDP servers to cause a d…

Patch available
Fix from $1,600 2014-01-03