Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

FreeRDP — Vulnerabilities & Security Advisories 158

All 158 CVE vulnerabilities found in FreeRDP, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumerations (CWE) related to the FreeRDP client and server implementation developed by FreeRDP. It serves as a centralized resource for security professionals and administrators seeking to understand the historical and current security posture of this widely used Remote Desktop Protocol client. The content collected includes vulnerabilities ranging from buffer overflows and memory corruption issues to protocol parsing errors and authentication bypasses. This collection spans various releases, covering both older legacy versions and recent updates to provide a comprehensive view of the software's security history. By exploring this aggregation, users can track advisories issued by the vendor and third-party security researchers to stay informed about emerging threats. It allows for a deeper understanding of specific weakness classes by contextualizing them within the FreeRDP codebase, helping developers identify common patterns in bug reports. Additionally, the page facilitates the lookup of a product’s vulnerability history, enabling organizations to assess their risk exposure based on their specific version deployment. This information supports better incident response planning and patch management strategies by highlighting which areas of the protocol implementation have been historically vulnerable. The goal is to provide clear, actionable data without redundancy, ensuring that security teams can quickly identify relevant risks associated with FreeRDP deployments in their infrastructure.

Vendor: FreeRDP

CVE IDTitleCVSSSeverityPublished
CVE-2026-57156 FreeRDP: Integer overflow leading to heap buffer overflow in Orders Delta Points parsing CWE-122--2026-07-10
CVE-2026-57157 Out-of-bounds read in the camera device enumerator server (rdpecam) via unterminated DeviceName / VirtualChannelName CWE-125 6.5 Medium2026-07-10
CVE-2026-57158 FreeRDP planar_decompress_plane_rle_only: heap OOB read — incomplete fix for CVE-2026-23530 CWE-125--2026-07-10
CVE-2026-55827 FreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decode CWE-131 7.5 High2026-07-10
CVE-2026-56297 FreeRDP - Use-After-Free via Race Condition in DRDYNVC Channel Callback CWE-362 7.0 High2026-07-08
CVE-2026-45700 Heap-buffer-overflow write in planar bitmap decoder CWE-787--2026-05-29
CVE-2026-44420 FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CLIP_CAPS CWE-122 8.8 High2026-05-29
CVE-2026-44422 FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and type confusion CWE-416 7.5 High2026-05-29
CVE-2026-44421 FreeRDP RDPGFX CacheToSurface heap-buffer-overflow via clamped-rectangle validation bypass CWE-122 8.8 High2026-05-29
CVE-2026-40033 FreeRDP - Heap-buffer-overflow in gdi_CacheToSurface via rectangle validation bypass CWE-122 8.8 High2026-05-26
CVE-2026-40254 FreeRDP: contains_dotdot() off-by-one allows drive channel path traversal via terminal .. CWE-193 4.2 Medium2026-04-24
CVE-2026-33995 FreeRDP: Possible double free in kerberos_AcceptSecurityContext CWE-415 5.3 Medium2026-03-30
CVE-2026-33987 FreeRDP: Persistent Cache bmpSize Desync - Heap OOB Write CWE-122 7.1 High2026-03-30
CVE-2026-33986 FreeRDP: H.264 YUV Buffer Dimension Desync - Heap OOB Write CWE-122 7.5 High2026-03-30
CVE-2026-33985 FreeRDP: ClearCodec Glyph Cache Count Desync - Heap OOB Read CWE-125 5.9 Medium2026-03-30
CVE-2026-33984 FreeRDP: ClearCodec resize_vbar_entry() Heap OOB Write CWE-122 7.5 High2026-03-30
CVE-2026-33983 FreeRDP: Progressive Codec Quant BYTE Underflow - UB + CPU DoS CWE-190 6.5 Medium2026-03-30
CVE-2026-33982 FreeRDP: Persistent Cache Allocator Mismatch - Heap OOB Read CWE-125 7.1 High2026-03-30
CVE-2026-33952 FreeRDP: DoS via WINPR_ASSERT in rts_read_auth_verifier_no_checks CWE-617 7.5 -2026-03-30
CVE-2026-33977 FreeRDP: DoS via WINPR_ASSERT in IMA ADPCM audio decoder (dsp.c:331) CWE-617 7.5 -2026-03-30
CVE-2026-31897 FreeRDP has an out-of-bounds read in `freerdp_bitmap_decompress_planar` CWE-125--2026-03-13
CVE-2026-31806 FreeRDP has a Heap Buffer Overflow in nsc_process_message() via Unchecked SURFACE_BITS_COMMAND Bitmap Dimensions CWE-122 9.1 -2026-03-13
CVE-2026-31885 FreeRDP has an out-of-bounds read in ADPCM decoders due to missing predictor/step_index bounds checks CWE-125 6.5 Medium2026-03-13
CVE-2026-31884 FreeRDP has a division-by-zero in ADPCM decoders when `nBlockAlign` is 0 CWE-369 6.5 Medium2026-03-13
CVE-2026-31883 FreeRDP has a `size_t` underflow in ADPCM decoder leads to heap-buffer-overflow write CWE-191 6.5 Medium2026-03-13
CVE-2026-29776 FreeRDP has an Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's Core Library CWE-190 3.1 Low2026-03-13
CVE-2026-29775 FreeRDP has a heap-buffer-overflow in bitmap_cache_put via OOB cacheId CWE-787 5.3 Medium2026-03-13
CVE-2026-29774 FreeRDP has a heap-buffer-overflow in avc420_yuv_to_rgb via OOB regionRects CWE-787 5.3 Medium2026-03-13
CVE-2026-27951 FreeRDP has possible Integer overflow in Stream_EnsureCapacity CWE-190 5.3 Medium2026-02-25
CVE-2026-27950 FreeRDP heap-use-after-free in update_pointer_new(SDL): Fix Applied in the Wrong File CWE-416 9.8AICriticalAI2026-02-25

All 158 known CVE vulnerabilities affecting FreeRDP with full Chinese analysis, references, and POCs where available.