Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

FreeRDP — Vulnerabilities & Security Advisories 184

All 184 CVE vulnerabilities found in FreeRDP, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumerations (CWE) related to the FreeRDP client and server implementation developed by FreeRDP. It serves as a centralized resource for security professionals and administrators seeking to understand the historical and current security posture of this widely used Remote Desktop Protocol client. The content collected includes vulnerabilities ranging from buffer overflows and memory corruption issues to protocol parsing errors and authentication bypasses. This collection spans various releases, covering both older legacy versions and recent updates to provide a comprehensive view of the software's security history. By exploring this aggregation, users can track advisories issued by the vendor and third-party security researchers to stay informed about emerging threats. It allows for a deeper understanding of specific weakness classes by contextualizing them within the FreeRDP codebase, helping developers identify common patterns in bug reports. Additionally, the page facilitates the lookup of a product’s vulnerability history, enabling organizations to assess their risk exposure based on their specific version deployment. This information supports better incident response planning and patch management strategies by highlighting which areas of the protocol implementation have been historically vulnerable. The goal is to provide clear, actionable data without redundancy, ensuring that security teams can quickly identify relevant risks associated with FreeRDP deployments in their infrastructure.

Vendor: FreeRDP

CVE IDTitleCVSSSeverityPublished
CVE-2023-39356 Missing offset validation leading to Out-of-Bounds Read in FreeRDP CWE-125 5.3 Medium2023-08-31
CVE-2023-39352 Invalid offset validation leading to Out Of Bound Write in FreeRDP CWE-787 5.3 Medium2023-08-31
CVE-2023-39353 Missing offset validation leading to Out Of Bound Read in FreeRDP CWE-125 5.3 Medium2023-08-31
CVE-2023-39351 FreeRDP Null Pointer Dereference leading denial of service CWE-476 5.3 Medium2023-08-31
CVE-2023-39355 FreeRDP Use-After-Free in RDPGFX_CMDID_RESETGRAPHICS CWE-416 7.0 High2023-08-31
CVE-2023-39354 FreeRDP Out-Of-Bounds Read in nsc_rle_decompress_data CWE-125 5.9 Medium2023-08-31
CVE-2023-39350 Incorrect offset calculation leading to denial of service in FreeRDP CWE-191 5.9 Medium2023-08-31
CVE-2023-40589 FreeRDP Global-Buffer-Overflow in ncrush_decompress CWE-120 4.3 Medium2023-08-31
CVE-2022-39316 Out of bound read in FreeRDP CWE-125 4.8 Medium2022-11-16
CVE-2022-39317 Out of bounds read in zgfx decoder in FreeRDP CWE-125 4.6 Medium2022-11-16
CVE-2022-39318 Division by zero in urbdrc channel in FreeRDP CWE-20 4.8 Medium2022-11-16
CVE-2022-39319 Missing length validation in urbdrc channel in FreeRDP CWE-125 4.6 Medium2022-11-16
CVE-2022-39320 Heap buffer overflow in urbdrc channel CWE-125 5.5 Medium2022-11-16
CVE-2022-39347 Missing path sanitation with `drive` channel in FreeRDP CWE-22 2.6 Low2022-11-16
CVE-2022-41877 Missing input length validation in `drive` channel in FreeRDP CWE-119 4.6 Medium2022-11-16
CVE-2022-39282 RDP client: Read of uninitialized memory with parallel port redirection CWE-908 3.5 Low2022-10-12
CVE-2022-39283 FreeRDP may read and display out of bounds data CWE-125 5.9 Medium2022-10-12
CVE-2022-24882 Server side NTLM does not properly check parameters in FreeRDP CWE-287 9.1 Critical2022-04-26
CVE-2022-24883 FreeRDP Server authentication might allow invalid credentials to pass CWE-287 7.4 High2022-04-26
CVE-2021-41159 Improper client input validation for FreeRDP gateway connections allows to overwrite memory CWE-787 5.8 Medium2021-10-21
CVE-2021-41160 Improper region checks in FreeRDP allow out of bound write to memory CWE-787 5.3 Medium2021-10-21
CVE-2020-15103 Integer Overflow in FreeRDP CWE-680 3.5 Low2020-07-27
CVE-2020-11095 Global OOB read in update_recv_primary_order in FreeRDP CWE-125 3.5 Low2020-06-22
CVE-2020-11096 Global OOB read in update_read_cache_bitmap_v3_order in FreeRDP CWE-125 3.5 Low2020-06-22
CVE-2020-11097 OOB read in ntlm_av_pair_get in FreeRDP CWE-125 3.5 Low2020-06-22
CVE-2020-11098 Out-of-bound read in glyph_cache_put in FreeRDP CWE-125 3.5 Low2020-06-22
CVE-2020-11099 OOB Read in license_read_new_or_upgrade_license_packet in FreeRDP CWE-125 3.5 Low2020-06-22
CVE-2020-4030 OOB read in `TrioParse` in FreeRDP CWE-125 3.5 Low2020-06-22
CVE-2020-4031 Use-After-Free in gdi_SelectObject in FreeRDP CWE-416 3.5 Low2020-06-22
CVE-2020-4032 Integer casting vulnerability in `update_recv_secondary_order` in FreeRDP CWE-681 3.1 Low2020-06-22

All 184 known CVE vulnerabilities affecting FreeRDP with full Chinese analysis, references, and POCs where available.