Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

FreeRDP — Vulnerabilities & Security Advisories 152

Browse all 152 CVE security advisories affecting FreeRDP. AI-powered Chinese analysis, POCs, and references for each vulnerability.

FreeRDP is an open-source Remote Desktop Protocol client and server implementation designed to facilitate cross-platform remote desktop connectivity. Its widespread adoption in enterprise and personal environments has made it a frequent target for security researchers, resulting in a significant number of recorded Common Vulnerabilities and Exposures. Historically, the codebase has been susceptible to critical remote code execution flaws, often stemming from improper input validation within the RDP protocol parsing logic. These vulnerabilities frequently allow attackers to execute arbitrary commands or escalate privileges on affected systems without user interaction. While the project maintains an active development cycle to patch these issues, the sheer volume of past incidents highlights the complexity of implementing secure network protocols. Continuous monitoring and timely updates remain essential for mitigating risks associated with its extensive feature set and legacy code dependencies.

Top products by FreeRDP: FreeRDP
CVE IDTitleCVSSSeverityPublished
CVE-2026-57156 FreeRDP: Integer overflow leading to heap buffer overflow in Orders Delta Points parsing — FreeRDPCWE-122--2026-07-10
CVE-2026-57157 Out-of-bounds read in the camera device enumerator server (rdpecam) via unterminated DeviceName / VirtualChannelName — FreeRDPCWE-125 6.5 Medium2026-07-10
CVE-2026-57158 FreeRDP planar_decompress_plane_rle_only: heap OOB read — incomplete fix for CVE-2026-23530 — FreeRDPCWE-125--2026-07-10
CVE-2026-55827 FreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decode — FreeRDPCWE-131 7.5 High2026-07-10
CVE-2026-56297 FreeRDP - Use-After-Free via Race Condition in DRDYNVC Channel Callback — FreeRDPCWE-362 7.0 High2026-07-08
CVE-2026-45700 Heap-buffer-overflow write in planar bitmap decoder — FreeRDPCWE-787--2026-05-29
CVE-2026-44420 FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CLIP_CAPS — FreeRDPCWE-122 8.8 High2026-05-29
CVE-2026-44422 FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and type confusion — FreeRDPCWE-416 7.5 High2026-05-29
CVE-2026-44421 FreeRDP RDPGFX CacheToSurface heap-buffer-overflow via clamped-rectangle validation bypass — FreeRDPCWE-122 8.8 High2026-05-29
CVE-2026-40033 FreeRDP - Heap-buffer-overflow in gdi_CacheToSurface via rectangle validation bypass — FreeRDPCWE-122 8.8 High2026-05-26
CVE-2026-40254 FreeRDP: contains_dotdot() off-by-one allows drive channel path traversal via terminal .. — FreeRDPCWE-193 4.2 Medium2026-04-24
CVE-2026-33995 FreeRDP: Possible double free in kerberos_AcceptSecurityContext — FreeRDPCWE-415 5.3 Medium2026-03-30
CVE-2026-33987 FreeRDP: Persistent Cache bmpSize Desync - Heap OOB Write — FreeRDPCWE-122 7.1 High2026-03-30
CVE-2026-33986 FreeRDP: H.264 YUV Buffer Dimension Desync - Heap OOB Write — FreeRDPCWE-122 7.5 High2026-03-30
CVE-2026-33985 FreeRDP: ClearCodec Glyph Cache Count Desync - Heap OOB Read — FreeRDPCWE-125 5.9 Medium2026-03-30
CVE-2026-33984 FreeRDP: ClearCodec resize_vbar_entry() Heap OOB Write — FreeRDPCWE-122 7.5 High2026-03-30
CVE-2026-33983 FreeRDP: Progressive Codec Quant BYTE Underflow - UB + CPU DoS — FreeRDPCWE-190 6.5 Medium2026-03-30
CVE-2026-33982 FreeRDP: Persistent Cache Allocator Mismatch - Heap OOB Read — FreeRDPCWE-125 7.1 High2026-03-30
CVE-2026-33952 FreeRDP: DoS via WINPR_ASSERT in rts_read_auth_verifier_no_checks — FreeRDPCWE-617 7.5 -2026-03-30
CVE-2026-33977 FreeRDP: DoS via WINPR_ASSERT in IMA ADPCM audio decoder (dsp.c:331) — FreeRDPCWE-617 7.5 -2026-03-30
CVE-2026-31897 FreeRDP has an out-of-bounds read in `freerdp_bitmap_decompress_planar` — FreeRDPCWE-125--2026-03-13
CVE-2026-31806 FreeRDP has a Heap Buffer Overflow in nsc_process_message() via Unchecked SURFACE_BITS_COMMAND Bitmap Dimensions — FreeRDPCWE-122 9.1 -2026-03-13
CVE-2026-31885 FreeRDP has an out-of-bounds read in ADPCM decoders due to missing predictor/step_index bounds checks — FreeRDPCWE-125 6.5 Medium2026-03-13
CVE-2026-31884 FreeRDP has a division-by-zero in ADPCM decoders when `nBlockAlign` is 0 — FreeRDPCWE-369 6.5 Medium2026-03-13
CVE-2026-31883 FreeRDP has a `size_t` underflow in ADPCM decoder leads to heap-buffer-overflow write — FreeRDPCWE-191 6.5 Medium2026-03-13
CVE-2026-29776 FreeRDP has an Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's Core Library — FreeRDPCWE-190 3.1 Low2026-03-13
CVE-2026-29775 FreeRDP has a heap-buffer-overflow in bitmap_cache_put via OOB cacheId — FreeRDPCWE-787 5.3 Medium2026-03-13
CVE-2026-29774 FreeRDP has a heap-buffer-overflow in avc420_yuv_to_rgb via OOB regionRects — FreeRDPCWE-787 5.3 Medium2026-03-13
CVE-2026-27951 FreeRDP has possible Integer overflow in Stream_EnsureCapacity — FreeRDPCWE-190 5.3 Medium2026-02-25
CVE-2026-27950 FreeRDP heap-use-after-free in update_pointer_new(SDL): Fix Applied in the Wrong File — FreeRDPCWE-416 9.8AICriticalAI2026-02-25

This page lists every published CVE security advisory associated with FreeRDP. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.