Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

FreeRDP — Vulnerabilities & Security Advisories 211

Browse all 211 CVE security advisories affecting FreeRDP. AI-powered Chinese analysis, POCs, and references for each vulnerability.

FreeRDP is an open-source Remote Desktop Protocol client and server implementation designed to facilitate cross-platform remote desktop connectivity. Its widespread adoption in enterprise and personal environments has made it a frequent target for security researchers, resulting in a significant number of recorded Common Vulnerabilities and Exposures. Historically, the codebase has been susceptible to critical remote code execution flaws, often stemming from improper input validation within the RDP protocol parsing logic. These vulnerabilities frequently allow attackers to execute arbitrary commands or escalate privileges on affected systems without user interaction. While the project maintains an active development cycle to patch these issues, the sheer volume of past incidents highlights the complexity of implementing secure network protocols. Continuous monitoring and timely updates remain essential for mitigating risks associated with its extensive feature set and legacy code dependencies.

Found 211 results / 211 Clear Filters
Top products by FreeRDP: FreeRDP
CVE ID Title CVSS Severity Published
CVE-2026-91963 FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc — FreeRDP CWE-457 6.5 Medium 2026-09-15
CVE-2026-91964 FreeRDP 2.0.0 through 3.30.0 Heap Buffer Overflow via RoutingToken — FreeRDP CWE-122 8.8 High 2026-09-15
CVE-2026-91962 FreeRDP before 3.31.0 Integer Overflow via audin Apple backends — FreeRDP CWE-131 6.3 Medium 2026-09-15
CVE-2026-91961 FreeRDP before 3.31.0 Denial of Service via URBDRC — FreeRDP CWE-617 6.5 Medium 2026-09-15
CVE-2026-91960 FreeRDP before 3.31.0 Integer Overflow Double Free — FreeRDP CWE-190 6.5 Medium 2026-09-15
CVE-2026-91959 FreeRDP before 3.31.0 Buffer Over-read via RTS Gateway — FreeRDP CWE-125 6.5 Medium 2026-09-15
CVE-2026-91957 FreeRDP before 3.31.0 Use-After-Free via smartcard worker — FreeRDP CWE-416 3.1 Low 2026-09-15
CVE-2026-91958 FreeRDP 3.11.0 through 3.30.0 Heap Buffer Overflow via Monitor Index — FreeRDP CWE-125 6.6 Medium 2026-09-15
CVE-2026-91956 FreeRDP before 3.31.0 Out-of-Bounds Read via URBDRC — FreeRDP CWE-125 6.5 Medium 2026-09-15
CVE-2026-91954 FreeRDP before 3.31.0 NULL Pointer Dereference via NSCodec — FreeRDP CWE-476 6.5 Medium 2026-09-15
CVE-2026-91955 FreeRDP before 3.31.0 Denial of Service via Desktop Dimensions — FreeRDP CWE-369 7.5 High 2026-09-15
CVE-2026-91953 FreeRDP before 3.31.0 Heap Buffer Overflow via LB_LOAD_BALANCE_INFO — FreeRDP CWE-120 6.5 Medium 2026-09-15
CVE-2026-91951 FreeRDP 3.14.0 through 3.30.0 Out-of-bounds Write via urbdrc — FreeRDP CWE-617 6.5 Medium 2026-09-15
CVE-2026-91952 FreeRDP before 3.31.0 Denial of Service via pool_decode_rect — FreeRDP CWE-835 6.5 Medium 2026-09-15
CVE-2026-91950 FreeRDP before 3.31.0 Out-of-Bounds Read via UINT32 Wraparound — FreeRDP CWE-125 6.5 Medium 2026-09-15
CVE-2026-91949 FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass — FreeRDP CWE-693 9.3 Critical 2026-09-15
CVE-2026-91948 FreeRDP before 3.31.0 Out-of-bounds Write via SHOW_PROTOCOL — FreeRDP CWE-191 7.5 High 2026-09-15
CVE-2026-91947 FreeRDP Server before 3.31.0 Use-After-Free via DRDYNVC — FreeRDP CWE-362 7.5 High 2026-09-15
CVE-2026-91946 FreeRDP before 3.31.0 Information Disclosure via RDPGFX ResetGraphics — FreeRDP CWE-908 6.5 Medium 2026-09-15
CVE-2026-91945 FreeRDP before 3.31.0 Out-of-bounds Read via Smartcard ATR — FreeRDP CWE-125 6.5 Medium 2026-09-15
CVE-2026-85090 FreeRDP before 3.31.0 Heap Out-of-Bounds Read via AVC444 — FreeRDP CWE-125 5.4 Medium 2026-09-03
CVE-2026-85089 FreeRDP before 3.31.0 Information Disclosure via uninitialized heap memory — FreeRDP CWE-908 6.5 Medium 2026-09-03
CVE-2026-63633 FreeRDP: Heap buffer overflow in Opus audio decode (`freerdp_dsp_decode_opus` resizes the wrong stream) — server→client — FreeRDP CWE-122 7.7 High 2026-08-19
CVE-2026-63652 FreeRDP: Double-free of `client_formats` in the rdpsnd server channel on a malformed Client Audio Formats PDU — FreeRDP CWE-415 7.1 High 2026-08-19
CVE-2026-63117 FreeRDP: Denial of service through ADPCM frame size calculation — FreeRDP CWE-369 6.5 Medium 2026-08-19
CVE-2026-55192 FreeRDP: Out-of-bounds read in H.264 YUV-to-RGB conversion due to decoder/surface dimension mismatch — FreeRDP CWE-125 7.2 High 2026-08-19
CVE-2026-55194 FreeRDPHeap-buffer-overflow write in TS Gateway RPC RESPONSE reassembly due to alloc_hint capacity mismatch — FreeRDP CWE-122 8.7 High 2026-08-19
CVE-2026-55648 FreeRDP: Integer Overflow in `freerdp_image_copy_from_icon_data` Bypasses Bounds Check — FreeRDP CWE-190 6.1 Medium 2026-08-19
CVE-2026-55193 FreeRDP: Heap-buffer-overflow write in TS Gateway RPC fragment receive due to uncapped bind_ack max_xmit_frag — FreeRDP CWE-122 8.7 High 2026-08-19
CVE-2026-55564 FreeRDP: Out-of-bounds read in glyph_cache_get via crafted glyph fragments — FreeRDP CWE-125 5.4 Medium 2026-08-19

This page lists every published CVE security advisory associated with FreeRDP. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.