<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 10:04:24 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:2208 — Moderate: freerdp security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:2208</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: freerdp, AlmaLinux:9: freerdp-devel, AlmaLinux:9: freerdp-libs, AlmaLinux:9: libwinpr, AlmaLinux:9: libwinpr-devel&lt;/p&gt;
&lt;p&gt;FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* freerdp: Incorrect offset calculation leading to DOS (CVE-2023-39350)
* freerdp: Null Pointer Dereference leading DOS in RemoteFX (CVE-2023-39351)
* freerdp: invalid offset validation leading to Out Of Bound Write (CVE-2023-39352)
* freerdp: missing offset validation leading to Out-of-Bounds Read in gdi_multi_opaque_rect (CVE-2023-39356)
* freerdp: Integer overflow leading to out-of-bound write vulnerability in gdi_CreateSurface (CVE-2023-40186)
* freerdp: Out-of-bounds write in clear_decompress_bands_data (CVE-2023-40567)
* freerdp: Out-of-bounds write in the `progressive_decompress` function due to incorrect calculations (CVE-2023-40569)
* freerdp: buffer overflow in ncrush_decompress causes crash with crafted input (CVE-2023-40589)
* freerdp: missing offset validation leading to Out Of Bound Read (CVE-2023-39353)
* freerdp: Out-Of-Bounds Read in nsc_rle_decompress_data (CVE-2023-39354)
* freerdp: integer-Underflow leading to Out-Of-Bound Read in zgfx_decompress_segment (CVE-2023-40181)
* freerdp: Out-of-bounds read in general_LumaToYUV444 (CVE-2023-40188)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: freerdp, AlmaLinux:9: freerdp-devel, AlmaLinux:9: freerdp-libs, AlmaLinux:9: libwinpr, AlmaLinux:9: libwinpr-devel&lt;/p&gt;
&lt;p&gt;FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* freerdp: Incorrect offset calculation leading to DOS (CVE-2023-39350)
* freerdp: Null Pointer Dereference leading DOS in RemoteFX (CVE-2023-39351)
* freerdp: invalid offset validation leading to Out Of Bound Write (CVE-2023-39352)
* freerdp: missing offset validation leading to Out-of-Bounds Read in gdi_multi_opaque_rect (CVE-2023-39356)
* freerdp: Integer overflow leading to out-of-bound write vulnerability in gdi_CreateSurface (CVE-2023-40186)
* freerdp: Out-of-bounds write in clear_decompress_bands_data (CVE-2023-40567)
* freerdp: Out-of-bounds write in the `progressive_decompress` function due to incorrect calculations (CVE-2023-40569)
* freerdp: buffer overflow in ncrush_decompress causes crash with crafted input (CVE-2023-40589)
* freerdp: missing offset validation leading to Out Of Bound Read (CVE-2023-39353)
* freerdp: Out-Of-Bounds Read in nsc_rle_decompress_data (CVE-2023-39354)
* freerdp: integer-Underflow leading to Out-Of-Bound Read in zgfx_decompress_segment (CVE-2023-40181)
* freerdp: Out-of-bounds read in general_LumaToYUV444 (CVE-2023-40188)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:2208</guid>
    </item>
    <item>
      <title>bdu:2023-05078</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-05078</link>
      <description>bdu:2023-05078</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-05078</guid>
    </item>
    <item>
      <title>cnvd-2024-23245</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2024-23245</link>
      <description>cnvd-2024-23245</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2024-23245</guid>
    </item>
    <item>
      <title>EUVD-2026-258079</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258079</link>
      <description>EUVD-2026-258079</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258079</guid>
    </item>
    <item>
      <title>fkie_cve-2023-39354</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-39354</link>
      <description>&lt;p&gt;FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Read in the `nsc_rle_decompress_data` function. The Out-Of-Bounds Read occurs because it processes `context-&amp;gt;Planes` without  checking if it contains data of sufficient length. Should an attacker be able to leverage this vulnerability they may be able to cause a crash. This issue has been addressed in versions 2.11.0 and 3.0.0-beta3. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Read in the `nsc_rle_decompress_data` function. The Out-Of-Bounds Read occurs because it processes `context-&amp;gt;Planes` without  checking if it contains data of sufficient length. Should an attacker be able to leverage this vulnerability they may be able to cause a crash. This issue has been addressed in versions 2.11.0 and 3.0.0-beta3. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-39354</guid>
    </item>
    <item>
      <title>gsd-2023-39354</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-39354</link>
      <description>gsd-2023-39354</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-39354</guid>
    </item>
    <item>
      <title>OESA-2023-1656 — freerdp security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1656</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: freerdp, openEuler:20.03-LTS-SP3: freerdp, openEuler:22.03-LTS: freerdp, openEuler:22.03-LTS-SP1: freerdp, openEuler:22.03-LTS-SP2: freerdp&lt;/p&gt;
&lt;p&gt;FreeRDP is a client implementation of the Remote Desktop Protocol (RDP) that follows Microsoft&amp;amp;apos;s open specifications. This package provides the client applications xfreerdp and wlfreerdp.&#13;
&#13;
Security Fix(es):&#13;
&#13;
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. This issue affects Clients only. Integer underflow leading to DOS (e.g. abort due to `WINPR_ASSERT` with default compilation flags). When an insufficient blockLen is provided, and proper length validation is not performed, an Integer Underflow occurs, leading to a Denial of Service (DOS) vulnerability. This issue has been addressed in versions 2.11.0 and 3.0.0-beta3. Users are advised to upgrade. There are no known workarounds for this vulnerability.
(CVE-2023-39350)&#13;
&#13;
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions of FreeRDP are subject to a Null Pointer Dereference leading a crash in the RemoteFX (rfx) handling.  Inside the `rfx_process_message_tileset` function, the program allocates tiles using `rfx_allocate_tiles` for the number of numTiles. If the initialization process of tiles is not completed for various reasons, tiles will have a NULL pointer. Which may be accessed in further processing and would cause a program crash. This issue has been addressed in versions 2.11.0 and 3.0.0-beta3. Users are advised to upgrade. There are no known workarounds for this vulnerability.(CVE-…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: freerdp, openEuler:20.03-LTS-SP3: freerdp, openEuler:22.03-LTS: freerdp, openEuler:22.03-LTS-SP1: freerdp, openEuler:22.03-LTS-SP2: freerdp&lt;/p&gt;
&lt;p&gt;FreeRDP is a client implementation of the Remote Desktop Protocol (RDP) that follows Microsoft&amp;amp;apos;s open specifications. This package provides the client applications xfreerdp and wlfreerdp.&#13;
&#13;
Security Fix(es):&#13;
&#13;
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. This issue affects Clients only. Integer underflow leading to DOS (e.g. abort due to `WINPR_ASSERT` with default compilation flags). When an insufficient blockLen is provided, and proper length validation is not performed, an Integer Underflow occurs, leading to a Denial of Service (DOS) vulnerability. This issue has been addressed in versions 2.11.0 and 3.0.0-beta3. Users are advised to upgrade. There are no known workarounds for this vulnerability.
(CVE-2023-39350)&#13;
&#13;
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions of FreeRDP are subject to a Null Pointer Dereference leading a crash in the RemoteFX (rfx) handling.  Inside the `rfx_process_message_tileset` function, the program allocates tiles using `rfx_allocate_tiles` for the number of numTiles. If the initialization process of tiles is not completed for various reasons, tiles will have a NULL pointer. Which may be accessed in further processing and would cause a program crash. This issue has been addressed in versions 2.11.0 and 3.0.0-beta3. Users are advised to upgrade. There are no known workarounds for this vulnerability.(CVE-…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1656</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13504-1 — freerdp-2.11.2-3.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13504-1</link>
      <description>&lt;p&gt;freerdp-2.11.2-3.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;freerdp-2.11.2-3.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13504-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:4611-1 — Security update for freerdp</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:4611-1</link>
      <description>&lt;p&gt;Security update for freerdp&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for freerdp&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:4611-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-39354</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-39354</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: freerdp2, Ubuntu:20.04:LTS: freerdp2, Ubuntu:22.04:LTS: freerdp2&lt;/p&gt;
&lt;p&gt;FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Read in the `nsc_rle_decompress_data` function. The Out-Of-Bounds Read occurs because it processes `context-&amp;gt;Planes` without checking if it contains data of sufficient length. Should an attacker be able to leverage this vulnerability they may be able to cause a crash. This issue has been addressed in versions 2.11.0 and 3.0.0-beta3. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: freerdp2, Ubuntu:20.04:LTS: freerdp2, Ubuntu:22.04:LTS: freerdp2&lt;/p&gt;
&lt;p&gt;FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Read in the `nsc_rle_decompress_data` function. The Out-Of-Bounds Read occurs because it processes `context-&amp;gt;Planes` without checking if it contains data of sufficient length. Should an attacker be able to leverage this vulnerability they may be able to cause a crash. This issue has been addressed in versions 2.11.0 and 3.0.0-beta3. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-39354</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2251 — FreeRDP: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2251</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in FreeRDP ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in FreeRDP ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2251</guid>
    </item>
  </channel>
</rss>
