Vulnerabilidades em FreeRDP

178 resultados
Análise Vexday

Com 147 CVEs catalogadas, o FreeRDP apresenta um volume considerável de vulnerabilidades históricas, embora a taxa de exploração ativa esteja abaixo da média geral do catálogo, sem registros no CISA KEV. O tipo de falha predominante é CWE-125 (leitura fora dos limites de buffer), padrão recorrente em clientes de protocolo remoto e que pode facilitar vazamento de dados ou instabilidade da aplicação. O CVE de maior atenção no momento é CVE-2024-32459, com score EPSS de 0,0375, e a existência de 2 CVEs com PoC pública exige monitoramento contínuo por parte de equipes de resposta. O ritmo de 15 novas CVEs nos últimos 90 dias indica superfície de ataque em expansão ativa, reforçando a necessidade de ciclos de atualização frequentes em ambientes que utilizam esta solução de desktop remoto.

CVE-2017-2834HIGHAn exploitable code execution vulnerability exists in the authentication functionality of FreeRDP 2.0.0-beta1+android11. A specially craftedEPSS 1.8%CVE-2020-4031LOWUse-After-Free in gdi_SelectObject in FreeRDPEPSS 1.8%CVE-2020-11042MEDIUMOut-of-bounds Read in FreeRDPEPSS 1.8%CVE-2017-2839MEDIUMAn exploitable denial of service vulnerability exists within the handling of challenge packets in FreeRDP 2.0.0-beta1+android11. A speciallyEPSS 1.7%CVE-2020-11047MEDIUMOut-of-bounds Read in FreeRDPEPSS 1.7%CVE-2020-11085LOWOut-of-bounds Read in FreeRDPEPSS 1.7%CVE-2020-11045LOWOut-of-bounds Read in FreeRDPEPSS 1.7%CVE-2020-11098LOWOut-of-bound read in glyph_cache_put in FreeRDPEPSS 1.7%CVE-2020-11058LOWImproper Restriction of Operations within the Bounds of a Memory Buffer in FreeRDPEPSS 1.6%CVE-2020-11040LOWOut-of-bounds Read in FreeRDPEPSS 1.6%CVE-2017-2837MEDIUMAn exploitable denial of service vulnerability exists within the handling of security data in FreeRDP 2.0.0-beta1+android11. A specially craEPSS 1.6%CVE-2017-2838MEDIUMAn exploitable denial of service vulnerability exists within the handling of challenge packets in FreeRDP 2.0.0-beta1+android11. A speciallyEPSS 1.6%CVE-2021-41160MEDIUMImproper region checks in FreeRDP allow out of bound write to memoryEPSS 1.6%CVE-2020-11041LOWImproper Validation of Array Index in FreeRDPEPSS 1.5%CVE-2023-39356MEDIUMMissing offset validation leading to Out-of-Bounds Read in FreeRDPEPSS 1.5%CVE-2020-11049MEDIUMOut-of-bounds Read in FreeRDPrdp_read_share_control_headerEPSS 1.5%CVE-2017-2835HIGHAn exploitable code execution vulnerability exists in the RDP receive functionality of FreeRDP 2.0.0-beta1+android11. A specially crafted seEPSS 1.5%CVE-2020-15103LOWInteger Overflow in FreeRDPEPSS 1.5%CVE-2020-11088LOWOut-of-bound read in FreeRDPEPSS 1.5%CVE-2020-11095LOWGlobal OOB read in update_recv_primary_order in FreeRDPEPSS 1.5%