Vulnerabilities in FreeRDP

211 results
Vexday analysis

Com 147 CVEs catalogadas, o FreeRDP apresenta um volume considerável de vulnerabilidades históricas, embora a taxa de exploração ativa esteja abaixo da média geral do catálogo, sem registros no CISA KEV. O tipo de falha predominante é CWE-125 (leitura fora dos limites de buffer), padrão recorrente em clientes de protocolo remoto e que pode facilitar vazamento de dados ou instabilidade da aplicação. O CVE de maior atenção no momento é CVE-2024-32459, com score EPSS de 0,0375, e a existência de 2 CVEs com PoC pública exige monitoramento contínuo por parte de equipes de resposta. O ritmo de 15 novas CVEs nos últimos 90 dias indica superfície de ataque em expansão ativa, reforçando a necessidade de ciclos de atualização frequentes em ambientes que utilizam esta solução de desktop remoto.

CVE-2022-41877MEDIUMMissing input length validation in `drive` channel in FreeRDPEPSS 0.8%CVE-2024-32662HIGHFreeRDP rdp_redirection_read_base64_wchar out of bound readEPSS 0.8%CVE-2026-22853MEDIUMFreeRDP has a heap-buffer-overflow in ndr_read_uint8ArrayEPSS 0.8%CVE-2022-39319MEDIUMMissing length validation in urbdrc channel in FreeRDPEPSS 0.8%CVE-2022-39320MEDIUMHeap buffer overflow in urbdrc channelEPSS 0.7%CVE-2026-57156HIGHFreeRDP: Integer overflow leading to heap buffer overflow in Orders Delta Points parsingEPSS 0.7%CVE-2026-22858MEDIUMFreeRDP has a global-buffer-overflow in crypto_base64_decodeEPSS 0.7%CVE-2022-39317MEDIUMOut of bounds read in zgfx decoder in FreeRDPEPSS 0.7%CVE-2026-31806CRITICALFreeRDP has a Heap Buffer Overflow in nsc_process_message() via Unchecked SURFACE_BITS_COMMAND Bitmap DimensionsEPSS 0.7%CVE-2026-24678HIGHFreeRDP has a Heap-use-after-free in cam_v4l_stream_capture_threadEPSS 0.7%CVE-2026-91948HIGHFreeRDP before 3.31.0 Out-of-bounds Write via SHOW_PROTOCOLEPSS 0.6%CVE-2026-91963HIGHFreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrcEPSS 0.6%CVE-2026-25952MEDIUMFreeRDP has heap-use-after-free in xf_SetWindowMinMaxInfoEPSS 0.6%CVE-2026-55191HIGHFreeRDP: Heap-buffer-overflow write in AVC444 YUV buffer allocationEPSS 0.6%CVE-2026-26965HIGHFreeRDP has Out-of-bounds WriteEPSS 0.6%CVE-2026-25953MEDIUMFreeRDP has heap-use-after-free in xf_AppUpdateWindowFromSurface (freed appWindow)EPSS 0.6%CVE-2026-91945HIGHFreeRDP before 3.31.0 Out-of-bounds Read via Smartcard ATREPSS 0.6%CVE-2026-25959MEDIUMFreeRDP has heap-use-after-free in xf_cliprdr_provide_data_EPSS 0.6%CVE-2026-25997MEDIUMFreeRDP has heap-use-after-free in xf_clipboard_format_equalEPSS 0.6%CVE-2026-23732MEDIUMFreeRDP has heap-buffer-overflow in Glyph_AllocEPSS 0.6%