Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

FreeRDP — Vulnerabilities & Security Advisories 211

Browse all 211 CVE security advisories affecting FreeRDP. AI-powered Chinese analysis, POCs, and references for each vulnerability.

FreeRDP is an open-source Remote Desktop Protocol client and server implementation designed to facilitate cross-platform remote desktop connectivity. Its widespread adoption in enterprise and personal environments has made it a frequent target for security researchers, resulting in a significant number of recorded Common Vulnerabilities and Exposures. Historically, the codebase has been susceptible to critical remote code execution flaws, often stemming from improper input validation within the RDP protocol parsing logic. These vulnerabilities frequently allow attackers to execute arbitrary commands or escalate privileges on affected systems without user interaction. While the project maintains an active development cycle to patch these issues, the sheer volume of past incidents highlights the complexity of implementing secure network protocols. Continuous monitoring and timely updates remain essential for mitigating risks associated with its extensive feature set and legacy code dependencies.

Top products by FreeRDP: FreeRDP
CVE ID Title CVSS Severity Published
CVE-2026-57157 Out-of-bounds read in the camera device enumerator server (rdpecam) via unterminated DeviceName / VirtualChannelName — FreeRDP CWE-125 6.5 Medium 2026-07-10
CVE-2026-57158 FreeRDP planar_decompress_plane_rle_only: heap OOB read — incomplete fix for CVE-2026-23530 — FreeRDP CWE-125 - - 2026-07-10
CVE-2026-55827 FreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decode — FreeRDP CWE-131 7.5 High 2026-07-10
CVE-2026-56297 FreeRDP - Use-After-Free via Race Condition in DRDYNVC Channel Callback — FreeRDP CWE-362 7.0 High 2026-07-08
CVE-2026-45700 Heap-buffer-overflow write in planar bitmap decoder — FreeRDP CWE-787 7.7 High 2026-05-29
CVE-2026-44420 FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CLIP_CAPS — FreeRDP CWE-122 8.8 High 2026-05-29
CVE-2026-44422 FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and type confusion — FreeRDP CWE-416 7.5 High 2026-05-29
CVE-2026-44421 FreeRDP RDPGFX CacheToSurface heap-buffer-overflow via clamped-rectangle validation bypass — FreeRDP CWE-122 8.8 High 2026-05-29
CVE-2026-40033 FreeRDP - Heap-buffer-overflow in gdi_CacheToSurface via rectangle validation bypass — FreeRDP CWE-122 8.8 High 2026-05-26
CVE-2026-40254 FreeRDP: contains_dotdot() off-by-one allows drive channel path traversal via terminal .. — FreeRDP CWE-193 4.2 Medium 2026-04-24
CVE-2026-33995 FreeRDP: Possible double free in kerberos_AcceptSecurityContext — FreeRDP CWE-415 5.3 Medium 2026-03-30
CVE-2026-33987 FreeRDP: Persistent Cache bmpSize Desync - Heap OOB Write — FreeRDP CWE-122 7.1 High 2026-03-30
CVE-2026-33986 FreeRDP: H.264 YUV Buffer Dimension Desync - Heap OOB Write — FreeRDP CWE-122 7.5 High 2026-03-30
CVE-2026-33985 FreeRDP: ClearCodec Glyph Cache Count Desync - Heap OOB Read — FreeRDP CWE-125 5.9 Medium 2026-03-30
CVE-2026-33984 FreeRDP: ClearCodec resize_vbar_entry() Heap OOB Write — FreeRDP CWE-122 7.5 High 2026-03-30
CVE-2026-33983 FreeRDP: Progressive Codec Quant BYTE Underflow - UB + CPU DoS — FreeRDP CWE-190 6.5 Medium 2026-03-30
CVE-2026-33982 FreeRDP: Persistent Cache Allocator Mismatch - Heap OOB Read — FreeRDP CWE-125 7.1 High 2026-03-30
CVE-2026-33952 FreeRDP: DoS via WINPR_ASSERT in rts_read_auth_verifier_no_checks — FreeRDP CWE-617 7.5 - 2026-03-30
CVE-2026-33977 FreeRDP: DoS via WINPR_ASSERT in IMA ADPCM audio decoder (dsp.c:331) — FreeRDP CWE-617 7.5 - 2026-03-30
CVE-2026-31897 FreeRDP has an out-of-bounds read in `freerdp_bitmap_decompress_planar` — FreeRDP CWE-125 - - 2026-03-13
CVE-2026-31806 FreeRDP has a Heap Buffer Overflow in nsc_process_message() via Unchecked SURFACE_BITS_COMMAND Bitmap Dimensions — FreeRDP CWE-122 9.1 - 2026-03-13
CVE-2026-31885 FreeRDP has an out-of-bounds read in ADPCM decoders due to missing predictor/step_index bounds checks — FreeRDP CWE-125 6.5 Medium 2026-03-13
CVE-2026-31884 FreeRDP has a division-by-zero in ADPCM decoders when `nBlockAlign` is 0 — FreeRDP CWE-369 6.5 Medium 2026-03-13
CVE-2026-31883 FreeRDP has a `size_t` underflow in ADPCM decoder leads to heap-buffer-overflow write — FreeRDP CWE-191 6.5 Medium 2026-03-13
CVE-2026-29776 FreeRDP has an Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's Core Library — FreeRDP CWE-190 3.1 Low 2026-03-13
CVE-2026-29775 FreeRDP has a heap-buffer-overflow in bitmap_cache_put via OOB cacheId — FreeRDP CWE-787 5.3 Medium 2026-03-13
CVE-2026-29774 FreeRDP has a heap-buffer-overflow in avc420_yuv_to_rgb via OOB regionRects — FreeRDP CWE-787 5.3 Medium 2026-03-13
CVE-2026-27951 FreeRDP has possible Integer overflow in Stream_EnsureCapacity — FreeRDP CWE-190 5.3 Medium 2026-02-25
CVE-2026-27950 FreeRDP heap-use-after-free in update_pointer_new(SDL): Fix Applied in the Wrong File — FreeRDP CWE-416 9.8AI Critical AI 2026-02-25
CVE-2026-26986 FreeRDP has heap-use-after-free in rail_window_free — FreeRDP CWE-416 5.5 Medium 2026-02-25

This page lists every published CVE security advisory associated with FreeRDP. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.