CVE-2014-0250

high
Published 2014-11-16 · Modified 2026-05-06
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Multiple integer overflows in client/X11/xf_graphics.c in FreeRDP allow remote attackers to have an unspecified impact via the width and height to the (1) xf_Pointer_New or (2) xf_Bitmap_Decompress function, which causes an incorrect amount of memory to be allocated.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/FreeRDP/FreeRDP/issues/1871

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://bugzilla.redhat.com/show_bug.cgi?id=998934

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2014-0250.html

OS impact

OSVersionStatusFixed in
suse slesaffected
suse suse13.1affected
suse suse12.3affected

Application impact

VendorProductVersionsFixed
freerdpfreerdp1.0.0
freerdpfreerdp1.0.1
freerdpfreerdp1.0.2

References

CWEs

CWE-189

Verify integrity in audit chain (admin only). AS-IS.