Vulnerabilities in FreeRDP

211 results
Vexday analysis

Com 147 CVEs catalogadas, o FreeRDP apresenta um volume considerável de vulnerabilidades históricas, embora a taxa de exploração ativa esteja abaixo da média geral do catálogo, sem registros no CISA KEV. O tipo de falha predominante é CWE-125 (leitura fora dos limites de buffer), padrão recorrente em clientes de protocolo remoto e que pode facilitar vazamento de dados ou instabilidade da aplicação. O CVE de maior atenção no momento é CVE-2024-32459, com score EPSS de 0,0375, e a existência de 2 CVEs com PoC pública exige monitoramento contínuo por parte de equipes de resposta. O ritmo de 15 novas CVEs nos últimos 90 dias indica superfície de ataque em expansão ativa, reforçando a necessidade de ciclos de atualização frequentes em ambientes que utilizam esta solução de desktop remoto.

CVE-2026-67290HIGHFreeRDP before 3.29.0 Heap Out-of-Bounds Read via TSMFEPSS 0.4%CVE-2026-33983MEDIUMFreeRDP: Progressive Codec Quant BYTE Underflow - UB + CPU DoSEPSS 0.4%CVE-2026-91953HIGHFreeRDP before 3.31.0 Heap Buffer Overflow via LB_LOAD_BALANCE_INFOEPSS 0.4%CVE-2026-22852MEDIUMFreeRDP has a heap-buffer-overflow in audin_process_formatsEPSS 0.4%CVE-2026-85089HIGHFreeRDP before 3.31.0 Information Disclosure via uninitialized heap memoryEPSS 0.4%CVE-2026-55648MEDIUMFreeRDP: Integer Overflow in `freerdp_image_copy_from_icon_data` Bypasses Bounds CheckEPSS 0.4%CVE-2026-33984HIGHFreeRDP: ClearCodec resize_vbar_entry() Heap OOB WriteEPSS 0.4%CVE-2026-67289CRITICALFreeRDP before 3.29.0 HTTP Proxy Request Injection via RedirectionEPSS 0.4%CVE-2026-63117MEDIUMFreeRDP: Denial of service through ADPCM frame size calculationEPSS 0.4%CVE-2026-73241HIGHFreeRDP: RDSTLS server authentication bypass: a credential-less Capabilities PDU is accepted at the auth step (fail-open `resultCode`)EPSS 0.4%CVE-2026-67298HIGHFreeRDP 3.28.0 Heap Buffer Overflow via RAIL orderLength UnderflowEPSS 0.4%CVE-2026-67304HIGHFreeRDP before 3.29.0 NULL Dereference via smartcard cleanupEPSS 0.4%CVE-2026-57157MEDIUMOut-of-bounds read in the camera device enumerator server (rdpecam) via unterminated DeviceName / VirtualChannelNameEPSS 0.4%CVE-2026-67296HIGHFreeRDP before 3.29.0 Denial of Service via RDPEI PDUEPSS 0.4%CVE-2026-67297HIGHFreeRDP before 3.29.0 Resource Exhaustion via chunked HTTP responseEPSS 0.4%CVE-2026-56297HIGHFreeRDP - Use-After-Free via Race Condition in DRDYNVC Channel CallbackEPSS 0.4%CVE-2026-67302MEDIUMFreeRDP rdpecam StartStreamsRequest divide-by-zero denial of serviceEPSS 0.4%CVE-2026-67291HIGHFreeRDP before 3.29.0 Heap Out-of-Bounds Read via GLYPH_FRAGMENT_ADDEPSS 0.4%CVE-2026-67301HIGHFreeRDP before 3.29.0 Out-of-bounds Read via Polygon async message-proxyEPSS 0.4%CVE-2026-73242HIGHFreeRDP: Kerberos GSS Wrap-token `EC` field is unbounded, causing an out-of-bounds decrypt in `kerberos_DecryptMessage`EPSS 0.4%