VDB

DEBIAN-CVE-2026-33985

DEBIAN-CVE-2026-33985 PUBLISHED CVSS 7.099999904632568 HIGH

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap memory is rendered to screen, potentially leaking sensitive data to the attacker. This issue has been patched in version 3.24.2.

Risk Scores

CVSS v3.1
7.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L

Affected Products

VendorProductVersions
Debian:12freerdp20, 2.10.0+dfsg1, 2.10.0+dfsg1
Debian:11freerdp22.11.7+dfsg1, 2.11.7+dfsg1, 2.11.7+dfsg1
Debian:14freerdp33.22.0+dfsg, 3.15.0+dfsg-2.1, 3.16.0+dfsg-1
Debian:13freerdp30, 3.15.0+dfsg-2.1, 3.16.0+dfsg-1

Timeline

  • Mar 30, 2026 CVE Published
  • May 16, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›