Search CVE reports


Toggle filters

161 – 170 of 228 results


CVE-2023-39354

Medium priority
Fixed

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Read in the `nsc_rle_decompress_data` function. The Out-Of-Bounds Read...

1 affected package

freerdp2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freerdp2 — — Fixed Fixed Fixed
Show less packages

CVE-2023-39351

Medium priority
Fixed

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions of FreeRDP are subject to a Null Pointer Dereference leading a crash in the RemoteFX (rfx) handling. ...

1 affected package

freerdp2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freerdp2 — — Fixed Fixed Fixed
Show less packages

CVE-2023-39350

Low priority
Fixed

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. This issue affects Clients only. Integer underflow leading to DOS (e.g. abort due to `WINPR_ASSERT` with default compilation...

1 affected package

freerdp2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freerdp2 — — Fixed Fixed Fixed
Show less packages

CVE-2023-40589

Medium priority
Fixed

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions there is a Global-Buffer-Overflow in the ncrush_decompress function. Feeding crafted input into this...

1 affected package

freerdp2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freerdp2 — — Fixed Fixed Fixed
Show less packages

CVE-2022-39347

Medium priority

Some fixes available 9 of 11

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for `drive` channel. A malicious server can trick a FreeRDP based client to read...

2 affected packages

freerdp2, freerdp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freerdp2 Not in release Fixed Fixed Fixed Fixed
freerdp — — Not in release Not in release Vulnerable
Show less packages

CVE-2022-39320

Low priority

Some fixes available 9 of 11

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP may attempt integer addition on too narrow types leads to allocation of a buffer too small holding the data written. A malicious server...

2 affected packages

freerdp2, freerdp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freerdp2 Not in release Fixed Fixed Fixed Fixed
freerdp — — Not in release Not in release Needs evaluation
Show less packages

CVE-2022-39319

Low priority

Some fixes available 9 of 11

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length validation in the `urbdrc` channel. A malicious server can trick a FreeRDP based client to read out of bound data...

2 affected packages

freerdp2, freerdp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freerdp2 Not in release Fixed Fixed Fixed Fixed
freerdp — — Not in release Not in release Vulnerable
Show less packages

CVE-2022-39318

Low priority

Some fixes available 9 of 11

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input validation in `urbdrc` channel. A malicious server can trick a FreeRDP based client to crash with division by zero. This...

2 affected packages

freerdp2, freerdp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freerdp2 Not in release Fixed Fixed Fixed Fixed
freerdp — — Not in release Not in release Vulnerable
Show less packages

CVE-2022-39317

Low priority

Some fixes available 9 of 11

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing a range check for input offset index in ZGFX decoder. A malicious server can trick a FreeRDP based client to read out of bound...

2 affected packages

freerdp2, freerdp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freerdp2 Not in release Fixed Fixed Fixed Fixed
freerdp — — Not in release Not in release Needs evaluation
Show less packages

CVE-2022-39316

Low priority
Fixed

FreeRDP is a free remote desktop protocol library and clients. In affected versions there is an out of bound read in ZGFX decoder component of FreeRDP. A malicious server can trick a FreeRDP based client to read out of bound data...

2 affected packages

freerdp2, freerdp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freerdp2 — — Fixed Fixed Fixed
freerdp — — Not in release Not in release Not affected
Show less packages