Neutrinolabs Xrdp vulnerabilities
41 known vulnerabilities affecting neutrinolabs/xrdp.
Total CVEs
41
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL17HIGH14MEDIUM10
Vulnerabilities
Page 2 of 3
CVE-2022-23483P3CRITICALCVSS 9.1fixed in 0.9.212022-12-09
CVE-2022-23483 [CRITICAL] CWE-125 CVE-2022-23483: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP).
xrdp < v0.9.21 contain a Out of Bound Read in libxrdp_send_to_channel() function. There are no known workarounds for this issue. Users are advised to upgrade.
nvdosv
CVE-2022-23481P3CRITICALCVSS 9.1fixed in 0.9.212022-12-09
CVE-2022-23481 [CRITICAL] CWE-125 CVE-2022-23481: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP).
xrdp < v0.9.21 contain a Out of Bound Read in xrdp_caps_process_confirm_active() function. There are no known workarounds for this issue. Users are advised to upgrade.
nvdosv
CVE-2022-23482P3CRITICALCVSS 9.1fixed in 0.9.212022-12-09
CVE-2022-23482 [CRITICAL] CWE-125 CVE-2022-23482: xrdp is an open source project which provides a graphical login to remote machines using Microsoft R
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP).
xrdp < v0.9.21 contain a Out of Bound Read in xrdp_sec_process_mcs_data_CS_CORE() function. There are no known workarounds for this issue. Users are advised to upgrade.
nvdosv
CVE-2026-33145P3MEDIUMCVSS 6.3fixed in 0.10.62026-04-17
CVE-2026-33145 [MEDIUM] CWE-78 CVE-2026-33145: xrdp is an open source RDP server. Versions through 0.10.5 allow an authenticated remote user to exe
xrdp is an open source RDP server. Versions through 0.10.5 allow an authenticated remote user to execute arbitrary commands on the server due to unsafe handling of the AlternateShell parameter in xrdp-sesman. When the AllowAlternateShell setting is enabled (which is the default when not explicitly configured), xrdp accepts a client-supplied Alternate
nvd
CVE-2020-4044P3HIGHCVSS 7.8fixed in 0.9.13.12020-06-30
CVE-2020-4044 [HIGH] CWE-121 CVE-2020-4044: The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supp
The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proceed to start their own imposter sesman service listening on port 3350. This will allow them to capture any user credentials that are sub
nvdosv
CVE-2013-1430P3CRITICALCVSS 9.8≤ 0.8.02016-12-16
CVE-2013-1430 [CRITICAL] CWE-255 CVE-2013-1430: An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp se
An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted with a known key.
nvdosv
CVE-2026-55626P3HIGHCVSS 7.3≥ 0.10.3, < 0.10.6.1fixed in 0.10.6.12026-07-20
CVE-2026-55626 [HIGH] CWE-287 CVE-2026-55626: xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session
xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using the Xvnc backend over UNIX domain sockets, the Xvnc process is launched with insufficient authentication mechanisms. A local authenticated attacker could exploit this vulnerability to bypass intended session isolation, allowing them
nvd
CVE-2022-23613P3HIGHCVSS 7.8v0.9.17v0.9.18+1 more2022-02-07
CVE-2022-23613 [HIGH] CWE-191 CVE-2022-23613: xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underfl
xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code as root. This vulnerability has been patched in version 0.9.18.1 and above. Users are advised to upgra
nvdosv
CVE-2008-5902P3HIGHCVSS 7.5≥ 0, < 0.4.0~dfsg-92009-01-15
CVE-2008-5902 [HIGH] CVE-2008-5902: Buffer overflow in the xrdp_bitmap_invalidate function in xrdp/xrdp_bitmap
Buffer overflow in the xrdp_bitmap_invalidate function in xrdp/xrdp_bitmap.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via a crafted request.
osv
CVE-2026-32624P3MEDIUMCVSS 6.5fixed in 0.10.62026-04-17
CVE-2026-32624 [MEDIUM] CWE-122 CVE-2026-32624: xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vuln
xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in its logon processing. In environments where domain_user_separator is configured in xrdp.ini, an unauthenticated remote attacker can send a crafted, excessively long username and domain name to overflow the internal buffer. This can corrup
nvd
CVE-2026-55645P3MEDIUMCVSS 6.5fixed in 0.10.6.12026-07-20
CVE-2026-55645 [MEDIUM] CWE-125 CVE-2026-55645: xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of Client Control PDUs. During the RDP connection sequence, the parser does not perform sufficient length validation before reading specific data fields from the network stream. A remote, unauthenticated attacker could potentially exploit th
nvd
CVE-2008-5903P3HIGHCVSS 7.5≥ 0, < 0.4.0~dfsg-92009-01-15
CVE-2008-5903 [HIGH] CVE-2008-5903: Array index error in the xrdp_bitmap_def_proc function in xrdp/funcs
Array index error in the xrdp_bitmap_def_proc function in xrdp/funcs.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via vectors that manipulate the value of the edit_pos structure member.
osv
CVE-2023-42822P3MEDIUMCVSS 6.5fixed in 0.9.23.12023-09-27
CVE-2023-42822 [MEDIUM] CWE-125 CVE-2023-42822: xrdp is an open source remote desktop protocol server. Access to the font glyphs in xrdp_painter.c i
xrdp is an open source remote desktop protocol server. Access to the font glyphs in xrdp_painter.c is not bounds-checked . Since some of this data is controllable by the user, this can result in an out-of-bounds read within the xrdp executable. The vulnerability allows an out-of-bounds read within a potentially privileged process. On non-Debian plat
nvdosv
CVE-2017-6967P4HIGHCVSS 7.3v0.9.12017-03-17
CVE-2017-6967 [HIGH] CWE-287 CVE-2017-6967: xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM sess
xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM session modules not being properly initialized, with a potential consequence of incorrect configurations or elevation of privileges, aka a pam_limits.so bypass.
nvdosv
CVE-2023-40184P3MEDIUMCVSS 6.5fixed in 0.9.232023-08-30
CVE-2023-40184 [MEDIUM] CWE-755 CVE-2023-40184: xrdp is an open source remote desktop protocol (RDP) server. In versions prior to 0.9.23 improper ha
xrdp is an open source remote desktop protocol (RDP) server. In versions prior to 0.9.23 improper handling of session establishment errors allows bypassing OS-level session restrictions. The `auth_start_session` function can return non-zero (1) value on, e.g., PAM error which may result in in session restrictions such as max concurrent sessions per
nvdosv
CVE-2017-16927P4HIGHCVSS 8.4≤ 0.9.42017-11-23
CVE-2017-16927 [HIGH] CWE-119 CVE-2017-16927: The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.
The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.
nvdosv
CVE-2026-55238P4MEDIUMCVSS 5.3fixed in 0.10.6.12026-07-20
CVE-2026-55238 [MEDIUM] CWE-126 CVE-2026-55238: xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Confirm Active PDU, where during the capability negotiation phase, the parser did not perform sufficient length validation for specific capability sets. A remote, unauthenticated attacker could potentially exploit this flaw by sending
nvd
CVE-2026-55639P4MEDIUMCVSS 5.3fixed in 0.10.6.12026-07-20
CVE-2026-55639 [MEDIUM] CWE-125 CVE-2026-55639: xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Security Data within the Client MCS Connect Initial PDU with GCC Conference Create Request during the connection sequence. During the initial capability and security negotiation phase, the parser fails to perform sufficient length val
nvd
CVE-2026-44978P4MEDIUMCVSS 5.3fixed in 0.10.6.12026-07-20
CVE-2026-44978 [MEDIUM] CWE-20 CVE-2026-44978: xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap out-of-bounds read vulne
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap out-of-bounds read vulnerability within the FIPS-specific receive paths. This vulnerability does not affect the default configuration of xrdp. The vulnerability is only exploitable when the security layer is set to security_layer=negotiate or security_layer=rdp, and the crypt
nvd
CVE-2026-42218P4MEDIUMCVSS 5.3fixed in 0.10.6.12026-07-20
CVE-2026-42218 [MEDIUM] CWE-204 CVE-2026-42218: xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerabi
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login interface. Due to a discrepancy in response processing times, a remote attacker can infer the existence of a username on the system, leading to unauthorized information disclosure via username enumeration. This issue has been fixed i
nvd