Home / CVEs we hold for Freerdp CVEs we hold for Freerdp Records whose assigning authority named Freerdp as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-91964 FreeRDP 2.0.0 through 3.30.0 Heap Buffer Overflow via RoutingToken FreeRDP CVE-2026-91963 FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc FreeRDP CVE-2026-91962 FreeRDP before 3.31.0 Integer Overflow via audin Apple backends FreeRDP CVE-2026-91961 FreeRDP before 3.31.0 Denial of Service via URBDRC FreeRDP CVE-2026-91960 FreeRDP before 3.31.0 Integer Overflow Double Free FreeRDP CVE-2026-91959 FreeRDP before 3.31.0 Buffer Over-read via RTS Gateway FreeRDP CVE-2026-91958 FreeRDP 3.11.0 through 3.30.0 Heap Buffer Overflow via Monitor Index FreeRDP CVE-2026-91957 FreeRDP before 3.31.0 Use-After-Free via smartcard worker FreeRDP CVE-2026-91956 FreeRDP before 3.31.0 Out-of-Bounds Read via URBDRC FreeRDP CVE-2026-91955 FreeRDP before 3.31.0 Denial of Service via Desktop Dimensions FreeRDP CVE-2026-91954 FreeRDP before 3.31.0 NULL Pointer Dereference via NSCodec FreeRDP CVE-2026-91953 FreeRDP before 3.31.0 Heap Buffer Overflow via LB_LOAD_BALANCE_INFO FreeRDP CVE-2026-91952 FreeRDP before 3.31.0 Denial of Service via pool_decode_rect FreeRDP CVE-2026-91951 FreeRDP 3.14.0 through 3.30.0 Out-of-bounds Write via urbdrc FreeRDP CVE-2026-91950 FreeRDP before 3.31.0 Out-of-Bounds Read via UINT32 Wraparound FreeRDP CVE-2026-91949 FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass FreeRDP CVE-2026-91948 FreeRDP before 3.31.0 Out-of-bounds Write via SHOW_PROTOCOL FreeRDP CVE-2026-91947 FreeRDP Server before 3.31.0 Use-After-Free via DRDYNVC FreeRDP CVE-2026-91946 FreeRDP before 3.31.0 Information Disclosure via RDPGFX ResetGraphics FreeRDP CVE-2026-91945 FreeRDP before 3.31.0 Out-of-bounds Read via Smartcard ATR FreeRDP CVE-2026-85090 FreeRDP before 3.31.0 Heap Out-of-Bounds Read via AVC444 FreeRDP CVE-2026-85089 FreeRDP before 3.31.0 Information Disclosure via uninitialized heap memory FreeRDP CVE-2026-73242 FreeRDP: Kerberos GSS Wrap-token `EC` field is unbounded, causing an out-of-bounds decrypt in `kerberos_DecryptMessage` FreeRDP CVE-2026-73241 FreeRDP: RDSTLS server authentication bypass: a credential-less Capabilities PDU is accepted at the auth step… FreeRDP CVE-2026-68580 FreeRDP before 3.29.0 Integer Overflow via Audio Input Channel FreeRDP CVE-2026-68579 FreeRDP before 3.30.0 Heap Overflow via CliprdrStream_Read FreeRDP CVE-2026-67306 FreeRDP before 3.29.0 Out-of-Bounds Read via Planar RLE FreeRDP CVE-2026-67305 FreeRDP Windows Client before 3.29.0 Heap Buffer Overflow via Cliprdr FreeRDP CVE-2026-67304 FreeRDP before 3.29.0 NULL Dereference via smartcard cleanup FreeRDP CVE-2026-67303 FreeRDP before 3.29.0 Denial of Service via serial DeviceControl FreeRDP CVE-2026-67302 FreeRDP rdpecam StartStreamsRequest divide-by-zero denial of service FreeRDP CVE-2026-67301 FreeRDP before 3.29.0 Out-of-bounds Read via Polygon async message-proxy FreeRDP CVE-2026-67300 FreeRDP before 3.29.0 Use-After-Free via async message proxy FreeRDP CVE-2026-67299 FreeRDP before 3.29.0 Use-After-Free via WindowIcon async message FreeRDP CVE-2026-67298 FreeRDP 3.28.0 Heap Buffer Overflow via RAIL orderLength Underflow FreeRDP CVE-2026-67297 FreeRDP before 3.29.0 Resource Exhaustion via chunked HTTP response FreeRDP CVE-2026-67296 FreeRDP before 3.29.0 Denial of Service via RDPEI PDU FreeRDP CVE-2026-67295 FreeRDP before 3.29.0 Path Traversal via drive redirection FreeRDP CVE-2026-67293 FreeRDP before 3.29.0 Improper Certificate Hostname Validation FreeRDP CVE-2026-67292 FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure FreeRDP CVE-2026-67291 FreeRDP before 3.29.0 Heap Out-of-Bounds Read via GLYPH_FRAGMENT_ADD FreeRDP CVE-2026-67290 FreeRDP before 3.29.0 Heap Out-of-Bounds Read via TSMF FreeRDP CVE-2026-67289 FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection FreeRDP CVE-2026-67288 FreeRDP before 3.29.0 Denial of Service via smartcard cache FreeRDP CVE-2026-66402 FreeRDP before 3.29.0 TLS Certificate Identity Validation Bypass FreeRDP CVE-2026-66401 FreeRDP before 3.29.0 Out-of-Bounds Read via UVC H.264 FreeRDP CVE-2026-64624 FreeRDP RDP File Parser Remote Code Execution via CLI Options FreeRDP CVE-2026-64621 FreeRDP before 3.28.0 Double-Free via selectedmonitors FreeRDP CVE-2026-64620 FreeRDP before 3.28.0 Heap Buffer Overflow via crypto_rsa_common FreeRDP CVE-2026-63652 FreeRDP: Double-free of `client_formats` in the rdpsnd server channel on a malformed Client Audio Formats PDU FreeRDP CVE-2026-63633 FreeRDP: Heap buffer overflow in Opus audio decode (`freerdp_dsp_decode_opus` resizes the wrong stream) — server→client FreeRDP CVE-2026-63117 FreeRDP: Denial of service through ADPCM frame size calculation FreeRDP CVE-2026-57158 FreeRDP planar_decompress_plane_rle_only: heap OOB read — incomplete fix for CVE-2026-23530 FreeRDP CVE-2026-57157 Out-of-bounds read in the camera device enumerator server (rdpecam) via unterminated DeviceName / VirtualChannelName FreeRDP CVE-2026-57156 FreeRDP: Integer overflow leading to heap buffer overflow in Orders Delta Points parsing FreeRDP CVE-2026-56297 FreeRDP - Use-After-Free via Race Condition in DRDYNVC Channel Callback FreeRDP CVE-2026-55827 FreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decode FreeRDP CVE-2026-55648 FreeRDP: Integer Overflow in `freerdp_image_copy_from_icon_data` Bypasses Bounds Check FreeRDP CVE-2026-55564 FreeRDP: Out-of-bounds read in glyph_cache_get via crafted glyph fragments FreeRDP CVE-2026-55194 FreeRDPHeap-buffer-overflow write in TS Gateway RPC RESPONSE reassembly due to alloc_hint capacity mismatch FreeRDP CVE-2026-55193 FreeRDP: Heap-buffer-overflow write in TS Gateway RPC fragment receive due to uncapped bind_ack max_xmit_frag FreeRDP CVE-2026-55192 FreeRDP: Out-of-bounds read in H.264 YUV-to-RGB conversion due to decoder/surface dimension mismatch FreeRDP CVE-2026-55191 FreeRDP: Heap-buffer-overflow write in AVC444 YUV buffer allocation FreeRDP CVE-2026-45700 Heap-buffer-overflow write in planar bitmap decoder FreeRDP CVE-2026-44422 FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and type confusion FreeRDP CVE-2026-44421 FreeRDP RDPGFX CacheToSurface heap-buffer-overflow via clamped-rectangle validation bypass FreeRDP CVE-2026-44420 FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CLIP_CAPS FreeRDP CVE-2026-40254 FreeRDP: contains_dotdot() off-by-one allows drive channel path traversal via terminal .. FreeRDP CVE-2026-40033 FreeRDP - Heap-buffer-overflow in gdi_CacheToSurface via rectangle validation bypass FreeRDP CVE-2026-33995 FreeRDP: Possible double free in kerberos_AcceptSecurityContext FreeRDP CVE-2026-33987 FreeRDP: Persistent Cache bmpSize Desync - Heap OOB Write FreeRDP CVE-2026-33986 FreeRDP: H.264 YUV Buffer Dimension Desync - Heap OOB Write FreeRDP CVE-2026-33985 FreeRDP: ClearCodec Glyph Cache Count Desync - Heap OOB Read FreeRDP CVE-2026-33984 FreeRDP: ClearCodec resize_vbar_entry() Heap OOB Write FreeRDP CVE-2026-33983 FreeRDP: Progressive Codec Quant BYTE Underflow - UB + CPU DoS FreeRDP CVE-2026-33982 FreeRDP: Persistent Cache Allocator Mismatch - Heap OOB Read FreeRDP CVE-2026-33977 FreeRDP: DoS via WINPR_ASSERT in IMA ADPCM audio decoder (dsp.c:331) FreeRDP CVE-2026-33952 FreeRDP: DoS via WINPR_ASSERT in rts_read_auth_verifier_no_checks FreeRDP CVE-2026-31897 FreeRDP has an out-of-bounds read in `freerdp_bitmap_decompress_planar` FreeRDP CVE-2026-31885 FreeRDP has an out-of-bounds read in ADPCM decoders due to missing predictor/step_index bounds checks FreeRDP CVE-2026-31884 FreeRDP has a division-by-zero in ADPCM decoders when `nBlockAlign` is 0 FreeRDP CVE-2026-31883 FreeRDP has a `size_t` underflow in ADPCM decoder leads to heap-buffer-overflow write FreeRDP CVE-2026-31806 FreeRDP has a Heap Buffer Overflow in nsc_process_message() via Unchecked SURFACE_BITS_COMMAND Bitmap Dimensions FreeRDP CVE-2026-29776 FreeRDP has an Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's Core Library FreeRDP CVE-2026-29775 FreeRDP has a heap-buffer-overflow in bitmap_cache_put via OOB cacheId FreeRDP CVE-2026-29774 FreeRDP has a heap-buffer-overflow in avc420_yuv_to_rgb via OOB regionRects FreeRDP CVE-2026-27951 FreeRDP has possible Integer overflow in Stream_EnsureCapacity FreeRDP CVE-2026-27950 FreeRDP heap-use-after-free in update_pointer_new(SDL): Fix Applied in the Wrong File FreeRDP CVE-2026-27015 FreeRDP: Smartcard NDR Alignment Padding Triggers Reachable WINPR_ASSERT Abort (Client DoS) FreeRDP CVE-2026-26986 FreeRDP has heap-use-after-free in rail_window_free FreeRDP CVE-2026-25997 FreeRDP has heap-use-after-free in xf_clipboard_format_equal FreeRDP CVE-2026-25959 FreeRDP has heap-use-after-free in xf_cliprdr_provide_data_ FreeRDP CVE-2026-25955 FreeRDP has heap-use-after-free in xf_AppUpdateWindowFromSurface (stale XImage) FreeRDP CVE-2026-25954 FreeRDP has heap-use-after-free in xf_rail_server_local_move_size FreeRDP CVE-2026-25953 FreeRDP has heap-use-after-free in xf_AppUpdateWindowFromSurface (freed appWindow) FreeRDP CVE-2026-25952 FreeRDP has heap-use-after-free in xf_SetWindowMinMaxInfo FreeRDP CVE-2026-25942 FreeRDP has global-buffer-overflow in xf_rail_server_execute_result FreeRDP CVE-2026-25941 FreeRDP: vuln_1_15_1 RDPGFX WIRE_TO_SURFACE_2 Out-of-Bounds Read FreeRDP CVE-2026-24683 FreeRDP has a heap-use-after-free in ainput_send_input_event FreeRDP CVE-2026-24682 FreeRDP has a Heap-buffer-overflow in audio_formats_free FreeRDP CVE-2026-24681 FreeRDP has a heap-use-after-free in urb_bulk_transfer_cb FreeRDP CVE-2026-24680 FreeRDP has a heap-use-after-free in update_pointer_new(SDL) FreeRDP CVE-2026-24679 FreeRDP has a heap-buffer-overflow in urb_select_interface FreeRDP CVE-2026-24678 FreeRDP has a Heap-use-after-free in cam_v4l_stream_capture_thread FreeRDP CVE-2026-24677 FreeRDP has a heap-buffer-overflow in ecam_encoder_compress_h264 FreeRDP CVE-2026-24676 FreeRDP has a heap-use-after-free in audio_format_compatible FreeRDP CVE-2026-24675 FreeRDP has a Heap-use-after-free in urb_select_interface FreeRDP CVE-2026-23948 FreeRDP has a NULL Pointer Dereference in rdp_write_logon_info_v2() FreeRDP CVE-2026-23534 FreeRDP has heap-buffer-overflow in clear_decompress_bands_data FreeRDP CVE-2026-23533 FreeRDP has heap-buffer-overflow in clear_decompress_residual_data FreeRDP CVE-2026-23532 FreeRDP has heap-buffer-overflow in gdi_SurfaceToSurface FreeRDP CVE-2026-23531 FreeRDP has heap-buffer-overflow in clear_decompress FreeRDP CVE-2026-23530 FreeRDP has heap-buffer-overflow in planar_decompress_plane_rle FreeRDP CVE-2026-22859 FreeRDP has a heap-buffer-overflow in urb_select_configuration FreeRDP CVE-2026-22858 FreeRDP has a global-buffer-overflow in crypto_base64_decode FreeRDP CVE-2026-22857 FreeRDP has a heap-use-after-free in irp_thread_func FreeRDP CVE-2026-22856 FreeRDP has a heap-use-after-free in create_irp_thread FreeRDP CVE-2026-22855 FreeRDP has a heap-buffer-overflow in smartcard_unpack_set_attrib_call FreeRDP CVE-2026-22854 FreeRDP has a heap-buffer-overflow in drive_process_irp_read FreeRDP CVE-2026-22853 FreeRDP has a heap-buffer-overflow in ndr_read_uint8Array FreeRDP CVE-2026-22852 FreeRDP has a heap-buffer-overflow in audin_process_formats FreeRDP CVE-2026-22851 FreeRDP RDPGFX ResetGraphics race leads to use-after-free in SDL client (sdl->primary) FreeRDP CVE-2025-68118 Potential Heap Out-of-Bounds Read in freerdp_certificate_data_hash_ via Unsafe _snprintf Usage FreeRDP CVE-2024-32662 FreeRDP rdp_redirection_read_base64_wchar out of bound read FreeRDP CVE-2024-32660 FreeRDP zgfx_decompress out of memory vulnerability FreeRDP CVE-2024-32658 FreeRDP ExtractRunLengthRegular* out of bound read FreeRDP CVE-2024-32460 FreeRDP Out-Of-Bounds Read in interleaved_decompress FreeRDP CVE-2024-32458 FreeRDP Out-Of-Bounds Read in planar_skip_plane_rle FreeRDP CVE-2024-32041 FreeRDP OutOfBound Read in zgfx_decompress_segment FreeRDP CVE-2024-32040 FreeRDP vulnerable to integer underflow in nsc_rle_decode FreeRDP CVE-2024-32039 FreeRDP Integer overflow & OutOfBound Write in clear_decompress_residual_data FreeRDP CVE-2024-22211 FreeRDP integer Overflow leading to Heap Overflow FreeRDP CVE-2023-40589 FreeRDP Global-Buffer-Overflow in ncrush_decompress FreeRDP CVE-2023-40186 IntegerOverflow leading to Out-Of-Bound Write Vulnerability in FreeRDP FreeRDP CVE-2023-40181 Integer-Underflow leading to Out-Of-Bound Read in FreeRDP FreeRDP CVE-2023-39356 Missing offset validation leading to Out-of-Bounds Read in FreeRDP FreeRDP CVE-2023-39355 FreeRDP Use-After-Free in RDPGFX_CMDID_RESETGRAPHICS FreeRDP CVE-2023-39354 FreeRDP Out-Of-Bounds Read in nsc_rle_decompress_data FreeRDP CVE-2023-39353 Missing offset validation leading to Out Of Bound Read in FreeRDP FreeRDP CVE-2023-39352 Invalid offset validation leading to Out Of Bound Write in FreeRDP FreeRDP CVE-2023-39351 FreeRDP Null Pointer Dereference leading denial of service FreeRDP CVE-2023-39350 Incorrect offset calculation leading to denial of service in FreeRDP FreeRDP CVE-2022-41877 Missing input length validation in `drive` channel in FreeRDP FreeRDP CVE-2022-39347 Missing path sanitation with `drive` channel in FreeRDP FreeRDP CVE-2022-39319 Missing length validation in urbdrc channel in FreeRDP FreeRDP CVE-2022-39282 RDP client: Read of uninitialized memory with parallel port redirection FreeRDP CVE-2022-24883 FreeRDP Server authentication might allow invalid credentials to pass FreeRDP CVE-2022-24882 Server side NTLM does not properly check parameters in FreeRDP FreeRDP CVE-2021-41160 Improper region checks in FreeRDP allow out of bound write to memory FreeRDP CVE-2021-41159 Improper client input validation for FreeRDP gateway connections allows to overwrite memory FreeRDP CVE-2020-4032 Integer casting vulnerability in `update_recv_secondary_order` in FreeRDP FreeRDP CVE-2020-4031 Use-After-Free in gdi_SelectObject in FreeRDP FreeRDP CVE-2020-11099 OOB Read in license_read_new_or_upgrade_license_packet in FreeRDP FreeRDP CVE-2020-11096 Global OOB read in update_read_cache_bitmap_v3_order in FreeRDP FreeRDP CVE-2020-11095 Global OOB read in update_recv_primary_order in FreeRDP FreeRDP CVE-2020-11086 Out-of-bounds Read in FreeRDP `ntlm_read_ntlm_v2_response` FreeRDP CVE-2020-11058 Improper Restriction of Operations within the Bounds of a Memory Buffer in FreeRDP FreeRDP CVE-2020-11049 Out-of-bounds Read in FreeRDPrdp_read_share_control_header FreeRDP CVE-2020-11048 Out-of-bounds Read in FreeRDPrdp_read_flow_control_pdu FreeRDP CVE-2020-11046 Improper Restriction of Operations within the Bounds of a Memory Buffer in FreeRDP FreeRDP 200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.