FreeRDP是FreeRDP团队的一款开源的远程桌面协议(RDP)的实现。 FreeRDP 3.24.2之前版本存在安全漏洞,该漏洞源于恶意RDP服务器发送具有无效初始步进索引值的IMA ADPCM格式音频数据,触发断言失败和进程中止,可能导致启用音频重定向的FreeRDP客户端崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33984 | 7.5 HIGH | FreeRDP: ClearCodec resize_vbar_entry() Heap OOB Write |
| CVE-2026-33986 | 7.5 HIGH | FreeRDP: H.264 YUV Buffer Dimension Desync - Heap OOB Write |
| CVE-2026-33982 | 7.1 HIGH | FreeRDP: Persistent Cache Allocator Mismatch - Heap OOB Read |
| CVE-2026-33987 | 7.1 HIGH | FreeRDP: Persistent Cache bmpSize Desync - Heap OOB Write |
| CVE-2026-33983 | 6.5 MEDIUM | FreeRDP: Progressive Codec Quant BYTE Underflow - UB + CPU DoS |
| CVE-2026-33985 | 5.9 MEDIUM | FreeRDP: ClearCodec Glyph Cache Count Desync - Heap OOB Read |
| CVE-2026-33995 | 5.3 MEDIUM | FreeRDP: Possible double free in kerberos_AcceptSecurityContext |
| CVE-2026-33952 | FreeRDP: DoS via WINPR_ASSERT in rts_read_auth_verifier_no_checks |
No comments yet