VendorsNeutrino Labsxrdpany version
Vulnerabilities

Neutrino Labs xrdp any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

35CVEs
CVE-2025-68670
xrdp improperly checks bounds of domain string length, which leads to Stack-based Buffer Overflow
Published 2026-01-27 · Analyzed
9.8EPSS 0.014
CVE-2013-1430
An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted with a known key.
Published 2016-12-16 · Modified
9.8EPSS 0.013
CVE-2026-41252
xrdp: lib_palette_update Heap Buffer Overflow & RCE
Published 2026-07-20 · Analyzed
9.8EPSS 0.011
CVE-2022-23477
Buffer Overflow in xrdp
Published 2022-12-09 · Modified
9.8EPSS 0.009
CVE-2022-23479
Buffer Overflow occurs in xrdp
Published 2022-12-09 · Modified
9.8EPSS 0.009
CVE-2022-23480
Buffer Overflow in xrdp
Published 2022-12-09 · Modified
9.8EPSS 0.009
CVE-2022-23478
Out of Bound Write in xrdp
Published 2022-12-09 · Modified
9.8EPSS 0.008
CVE-2022-23468
Buffer Overflow in xrdp
Published 2022-12-09 · Modified
9.8EPSS 0.008
CVE-2022-23484
Integer Overflow in xrdp
Published 2022-12-09 · Modified
9.8EPSS 0.008
CVE-2024-39917
xrdp allows an ininite number of login attempts
Published 2024-07-12 · Modified
9.8EPSS 0.006
CVE-2026-32105
xrdp: RDP MAC signature (dataSignature) never verified on receive — integrity bypass in non-TLS mode
Published 2026-04-17 · Analyzed
9.3EPSS 0.002
CVE-2022-23493
Out of Bound Read in xrdp
Published 2022-12-09 · Modified
9.1EPSS 0.009
CVE-2022-23483
Out-of-Bound Read in libxrdp
Published 2022-12-09 · Modified
9.1EPSS 0.009
CVE-2026-33689
xrdp: Pre-authentication out-of-bounds reads in channel parsers
Published 2026-04-17 · Analyzed
9.1EPSS 0.009
CVE-2022-23482
Out-of-Bound Read in xrdp
Published 2022-12-09 · Modified
9.1EPSS 0.008
CVE-2022-23481
Out-of-Bound Read in xrdp
Published 2022-12-09 · Modified
9.1EPSS 0.008
CVE-2026-33516
xrdp: Pre-authentication out-of-bounds reads in RDP capability and channel parsers
Published 2026-04-17 · Analyzed
9.1EPSS 0.007
CVE-2026-41521
xrdp: lib_framebuffer_update Has Integer Overflow Heap Info Leak & ASLR Bypass
Published 2026-07-20 · Analyzed
9.1EPSS 0.007
CVE-2026-35512
xrdp: Heap buffer overflow in EGFX channel
Published 2026-04-17 · Analyzed
8.8EPSS 0.010
CVE-2026-44178
xrdp: Channel Data Forwarding Fixed-Size Buffer Overflow
Published 2026-07-20 · Analyzed
8.8EPSS 0.009
CVE-2026-32107
xrdp: Fail-open privilege drop in sesexec — child processes may execute as root if setuid fails
Published 2026-04-17 · Analyzed
8.8EPSS 0.002
CVE-2017-16927
The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.
Published 2017-11-23 · Modified
8.4EPSS 0.004
CVE-2026-32623
xrdp: Heap buffer overflow in NeutrinoRDP channel reassembly
Published 2026-04-17 · Analyzed
8.1EPSS 0.008
CVE-2026-55626
xrdp: No authentication required with Xvnc backend on RHEL 9
Published 2026-07-20 · Analyzed
8.0EPSS 0.002
CVE-2020-4044
Local users can perform a buffer overflow attack against the xrdp-sesman service and then impersonate it
Published 2020-06-30 · Modified
7.8EPSS 0.024
CVE-2026-54538
xrdp: Pre-auth infinite loop via totalLength=0 in TS_SHARECONTROLHEADER
Published 2026-07-20 · Analyzed
7.5EPSS 0.007
CVE-2023-40184
Improper handling of session establishment errors in xrdp
Published 2023-08-30 · Modified
6.5EPSS 0.009
CVE-2023-42822
Unchecked access to font glyph info in xrdp
Published 2023-09-27 · Modified
6.5EPSS 0.006
CVE-2026-32624
xrdp: Heap buffer overflow in xrdp_sec_process_logon_info() via incorrect g_strncat length calculation
Published 2026-04-17 · Analyzed
6.5EPSS 0.005
CVE-2026-55645
xrdp: Out-of-bounds read in Client Control PDU processing (xrdp_rdp_process_data_control)
Published 2026-07-20 · Analyzed
6.5EPSS 0.005
CVE-2026-33145
xrdp: Authenticated RCE via unsanitized AlternateShell execution in xrdp-sesman
Published 2026-04-17 · Analyzed
6.3EPSS 0.006
CVE-2026-44978
xrdp: Unchecked FIPS padding length in standard RDP Security causes heap out-of-bounds read in HMAC verification
Published 2026-07-20 · Analyzed
5.3EPSS 0.005
CVE-2026-55238
xrdp: Malformed Confirm Active capability sets cause out-of-bounds reads
Published 2026-07-20 · Analyzed
5.3EPSS 0.005
CVE-2026-55639
xrdp: Out-of-bounds read in GCC Conference Create Request CS_SECURITY processing (xrdp_sec_process_mcs_data_CS_SECURITY)
Published 2026-07-20 · Analyzed
5.3EPSS 0.004
CVE-2026-42218
XRDP is vulnerable to a server timing attack, leading to user enumeration
Published 2026-07-20 · Analyzed
5.3EPSS 0.004