24h | 7d | 30d

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 3 Interactions

Last activity: 4 hours ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 3 Interactions

Last activity: 4 hours ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 3 Interactions

Last activity: 4 hours ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 3 Interactions

Last activity: 4 hours ago

Overview

  • FreeRDP
  • FreeRDP

14 Jan 2026
Published
14 Jan 2026
Updated

CVSS v4.0
MEDIUM (5.6)
EPSS
Pending

KEV

Description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap out-of-bounds read occurs in the smartcard SetAttrib path when cbAttrLen does not match the actual NDR buffer length. This vulnerability is fixed in 3.20.1.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 3 hours ago

Overview

  • FreeRDP
  • FreeRDP

14 Jan 2026
Published
14 Jan 2026
Updated

CVSS v4.0
MEDIUM (6.8)
EPSS
Pending

KEV

Description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client when processing Audio Input (AUDIN) format lists. audin_process_formats reuses callback->formats_count across multiple MSG_SNDIN_FORMATS PDUs and writes past the newly allocated formats array, causing memory corruption and a crash. This vulnerability is fixed in 3.20.1.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 3 hours ago

Overview

  • FreeRDP
  • FreeRDP

14 Jan 2026
Published
14 Jan 2026
Updated

CVSS v4.0
MEDIUM (6.9)
EPSS
Pending

KEV

Description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race condition between the RDPGFX dynamic virtual channel thread and the SDL render thread leads to a heap use-after-free. Specifically, an escaped pointer to sdl->primary (SDL_Surface) is accessed after it has been freed during RDPGFX ResetGraphics handling. This vulnerability is fixed in 3.20.1.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 3 hours ago

Overview

  • FreeRDP
  • FreeRDP

14 Jan 2026
Published
14 Jan 2026
Updated

CVSS v4.0
MEDIUM (6.8)
EPSS
Pending

KEV

Description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap-buffer-overflow occurs in drive read when a server-controlled read length is used to read file data into an IRP output stream buffer without a hard upper bound, allowing an oversized read to overwrite heap memory. This vulnerability is fixed in 3.20.1.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 3 hours ago

Overview

  • FreeRDP
  • FreeRDP

14 Jan 2026
Published
14 Jan 2026
Updated

CVSS v4.0
MEDIUM (6.8)
EPSS
Pending

KEV

Description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated from hints, causing a heap buffer overflow in ndr_read_uint8Array. This vulnerability is fixed in 3.20.1.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 3 hours ago

Overview

  • FreeRDP
  • FreeRDP

14 Jan 2026
Published
14 Jan 2026
Updated

CVSS v4.0
MEDIUM (6.8)
EPSS
Pending

KEV

Description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_thread_func because the IRP is freed by irp->Complete() and then accessed again on the error path. This vulnerability is fixed in 3.20.1.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 3 hours ago
Showing 71 to 80 of 83 CVEs