In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-11095
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-11095