freerdp
23 known vulnerabilities affecting freerdp products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-45700 | High | 4.4% | 9.8 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0… | |
| CVE-2026-64620 | High | 0.9% | 9.8 | FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow … | |
| CVE-2026-44420 | Medium | 3.7% | 8.8 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0… | |
| CVE-2026-40033 | Medium | 1.0% | 8.8 | FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_Cache… | |
| CVE-2026-67305 | Medium | 0.5% | 8.8 | FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerabili… | |
| CVE-2026-44421 | Medium | 0.5% | 8.8 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0… | |
| CVE-2026-44422 | Medium | 0.4% | 7.5 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0… | |
| CVE-2026-67304 | Medium | 0.4% | 7.5 | FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smart… | |
| CVE-2026-67297 | Medium | 0.4% | 7.5 | FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing T… | |
| CVE-2026-67296 | Medium | 0.4% | 7.5 | FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI se… | |
| CVE-2026-67301 | Medium | 0.4% | 7.5 | FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async u… | |
| CVE-2026-67291 | Medium | 0.4% | 7.5 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bound… | |
| CVE-2026-67288 | Medium | 0.3% | 7.5 | FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smart… | |
| CVE-2026-67299 | Medium | 0.3% | 7.5 | FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async up… | |
| CVE-2026-64621 | Medium | 0.3% | 7.3 | FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulne… | |
| CVE-2026-64624 | Medium | 0.2% | 7.8 | FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as … | |
| CVE-2026-85089 | Low | 0.4% | 6.5 | FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized hea… | |
| CVE-2026-67302 | Low | 0.4% | 4.3 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a divide-by-zero vu… | |
| CVE-2026-67292 | Low | 0.3% | 6.5 | FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gat… | |
| CVE-2026-85090 | Low | 0.3% | 5.4 | FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the ge… | |
| CVE-2026-67306 | Low | 0.3% | 5.4 | FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability … | |
| CVE-2026-67294 | Low | 0.3% | 5.9 | FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose … | |
| CVE-2026-66401 | Low | 0.2% | 2.1 | FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the U… |