Neutrinolabs Xrdp vulnerabilities

23 known vulnerabilities affecting neutrinolabs/xrdp.

Total CVEs
23
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL13HIGH7MEDIUM3

Vulnerabilities

Page 1 of 2
CVE-2025-68670CRITICALCVSS 9.8fixed in 0.10.52026-01-27
CVE-2025-68670 [CRITICAL] CWE-121 CVE-2025-68670: xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffe xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code on the target syst
cvelistv5nvdosv
CVE-2024-39917CRITICALCVSS 9.8fixed in 0.10.0≤ 0.10.02024-07-12
CVE-2024-39917 [CRITICAL] CWE-307 CVE-2024-39917: xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows at xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows attackers to make an infinite number of login attempts. The number of max login attempts is supposed to be limited by a configuration parameter `MaxLoginRetry` in `/etc/xrdp/sesman.ini`. However, this mechanism was not effectively working. As a result
cvelistv5nvdosv
CVE-2023-42822MEDIUMCVSS 6.5fixed in 0.9.23.12023-09-27
CVE-2023-42822 [MEDIUM] CWE-125 CVE-2023-42822: xrdp is an open source remote desktop protocol server. Access to the font glyphs in xrdp_painter.c i xrdp is an open source remote desktop protocol server. Access to the font glyphs in xrdp_painter.c is not bounds-checked . Since some of this data is controllable by the user, this can result in an out-of-bounds read within the xrdp executable. The vulnerability allows an out-of-bounds read within a potentially privileged process. On non-Debian plat
cvelistv5nvdosv
CVE-2023-40184MEDIUMCVSS 6.5fixed in 0.9.232023-08-30
CVE-2023-40184 [MEDIUM] CWE-755 CVE-2023-40184: xrdp is an open source remote desktop protocol (RDP) server. In versions prior to 0.9.23 improper ha xrdp is an open source remote desktop protocol (RDP) server. In versions prior to 0.9.23 improper handling of session establishment errors allows bypassing OS-level session restrictions. The `auth_start_session` function can return non-zero (1) value on, e.g., PAM error which may result in in session restrictions such as max concurrent sessions per
cvelistv5nvdosv
CVE-2022-23480CRITICALCVSS 9.8fixed in 0.9.212022-12-09
CVE-2022-23480 [CRITICAL] CWE-120 CVE-2022-23480: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in devredir_proc_client_devlist_announce_req() function. There are no known workarounds for this issue. Users are advised to upgrade.
cvelistv5nvdosv
CVE-2022-23481CRITICALCVSS 9.1fixed in 0.9.212022-12-09
CVE-2022-23481 [CRITICAL] CWE-125 CVE-2022-23481: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_caps_process_confirm_active() function. There are no known workarounds for this issue. Users are advised to upgrade.
cvelistv5nvdosv
CVE-2022-23468CRITICALCVSS 9.8fixed in 0.9.212022-12-09
CVE-2022-23468 [CRITICAL] CWE-120 CVE-2022-23468: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_login_wnd_create() function. There are no known workarounds for this issue. Users are advised to upgrade.
cvelistv5nvdosv
CVE-2022-23483CRITICALCVSS 9.1fixed in 0.9.212022-12-09
CVE-2022-23483 [CRITICAL] CWE-125 CVE-2022-23483: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in libxrdp_send_to_channel() function. There are no known workarounds for this issue. Users are advised to upgrade.
cvelistv5nvdosv
CVE-2022-23484CRITICALCVSS 9.8fixed in 0.9.212022-12-09
CVE-2022-23484 [CRITICAL] CWE-190 CVE-2022-23484: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Integer Overflow in xrdp_mm_process_rail_update_window_text() function. There are no known workarounds for this issue. Users are advised to upgrade.
cvelistv5nvdosv
CVE-2022-23479CRITICALCVSS 9.8fixed in 0.9.212022-12-09
CVE-2022-23479 [CRITICAL] CWE-120 CVE-2022-23479: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_mm_chan_data_in() function. There are no known workarounds for this issue. Users are advised to upgrade.
cvelistv5nvdosv
CVE-2022-23478CRITICALCVSS 9.8fixed in 0.9.212022-12-09
CVE-2022-23478 [CRITICAL] CWE-787 CVE-2022-23478: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Write in xrdp_mm_trans_process_drdynvc_channel_open() function. There are no known workarounds for this issue. Users are advised to upgrade.
cvelistv5nvdosv
CVE-2022-23493CRITICALCVSS 9.1fixed in 0.9.212022-12-09
CVE-2022-23493 [CRITICAL] CWE-125 CVE-2022-23493: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_mm_trans_process_drdynvc_channel_close() function. There are no known workarounds for this issue. Users are advised to upgrade.
cvelistv5nvdosv
CVE-2022-23482CRITICALCVSS 9.1fixed in 0.9.212022-12-09
CVE-2022-23482 [CRITICAL] CWE-125 CVE-2022-23482: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_sec_process_mcs_data_CS_CORE() function. There are no known workarounds for this issue. Users are advised to upgrade.
cvelistv5nvdosv
CVE-2022-23477CRITICALCVSS 9.8fixed in 0.9.212022-12-09
CVE-2022-23477 [CRITICAL] CWE-120 CVE-2022-23477: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in audin_send_open() function. There are no known workarounds for this issue. Users are advised to upgrade.
cvelistv5nvdosv
CVE-2022-23613HIGHCVSS 7.8v0.9.17v0.9.18+1 more2022-02-07
CVE-2022-23613 [HIGH] CWE-191 CVE-2022-23613: xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underfl xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code as root. This vulnerability has been patched in version 0.9.18.1 and above. Users are advised to upgra
cvelistv5nvdosv
CVE-2021-36158MEDIUMCVSS 5.9≥ 0, < 0.9.11-r12021-07-05
CVE-2021-36158 [MEDIUM] CVE-2021-36158: In the xrdp package (in branches through 3 In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used.
osv
CVE-2020-4044HIGHCVSS 7.8fixed in 0.9.13.12020-06-30
CVE-2020-4044 [HIGH] CWE-121 CVE-2020-4044: The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supp The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proceed to start their own imposter sesman service listening on port 3350. This will allow them to capture any user credentials that are sub
cvelistv5nvdosv
CVE-2017-16927HIGHCVSS 8.4≤ 0.9.42017-11-23
CVE-2017-16927 [HIGH] CWE-119 CVE-2017-16927: The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9. The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.
nvdosv
CVE-2017-6967HIGHCVSS 7.3v0.9.12017-03-17
CVE-2017-6967 [HIGH] CWE-287 CVE-2017-6967: xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM sess xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM session modules not being properly initialized, with a potential consequence of incorrect configurations or elevation of privileges, aka a pam_limits.so bypass.
nvdosv
CVE-2013-1430CRITICALCVSS 9.8≤ 0.8.02016-12-16
CVE-2013-1430 [CRITICAL] CWE-255 CVE-2013-1430: An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp se An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted with a known key.
nvdosv