cbcvebase.

Neutrinolabs Xrdp vulnerabilities

31 known vulnerabilities affecting neutrinolabs/xrdp.

Total CVEs
31
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH11MEDIUM5

Vulnerabilities

Page 2 of 2
CVE-2013-1430P3CRITICALCVSS 9.8≤ 0.8.02016-12-16
CVE-2013-1430 [CRITICAL] CWE-255 CVE-2013-1430: An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp se An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted with a known key.
nvdosv
CVE-2022-23613P3HIGHCVSS 7.8v0.9.17v0.9.18+1 more2022-02-07
CVE-2022-23613 [HIGH] CWE-191 CVE-2022-23613: xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underfl xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code as root. This vulnerability has been patched in version 0.9.18.1 and above. Users are advised to upgra
nvdosv
CVE-2026-33145P3MEDIUMCVSS 6.3fixed in 0.10.62026-04-17
CVE-2026-33145 [MEDIUM] CWE-78 CVE-2026-33145: xrdp is an open source RDP server. Versions through 0.10.5 allow an authenticated remote user to exe xrdp is an open source RDP server. Versions through 0.10.5 allow an authenticated remote user to execute arbitrary commands on the server due to unsafe handling of the AlternateShell parameter in xrdp-sesman. When the AllowAlternateShell setting is enabled (which is the default when not explicitly configured), xrdp accepts a client-supplied Alternate
nvd
CVE-2008-5902P3HIGHCVSS 7.5≥ 0, < 0.4.0~dfsg-92009-01-15
CVE-2008-5902 [HIGH] CVE-2008-5902: Buffer overflow in the xrdp_bitmap_invalidate function in xrdp/xrdp_bitmap Buffer overflow in the xrdp_bitmap_invalidate function in xrdp/xrdp_bitmap.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via a crafted request.
osv
CVE-2026-32624P3MEDIUMCVSS 6.5fixed in 0.10.62026-04-17
CVE-2026-32624 [MEDIUM] CWE-122 CVE-2026-32624: xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vuln xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in its logon processing. In environments where domain_user_separator is configured in xrdp.ini, an unauthenticated remote attacker can send a crafted, excessively long username and domain name to overflow the internal buffer. This can corrup
nvd
CVE-2008-5903P3HIGHCVSS 7.5≥ 0, < 0.4.0~dfsg-92009-01-15
CVE-2008-5903 [HIGH] CVE-2008-5903: Array index error in the xrdp_bitmap_def_proc function in xrdp/funcs Array index error in the xrdp_bitmap_def_proc function in xrdp/funcs.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via vectors that manipulate the value of the edit_pos structure member.
osv
CVE-2023-42822P3MEDIUMCVSS 6.5fixed in 0.9.23.12023-09-27
CVE-2023-42822 [MEDIUM] CWE-125 CVE-2023-42822: xrdp is an open source remote desktop protocol server. Access to the font glyphs in xrdp_painter.c i xrdp is an open source remote desktop protocol server. Access to the font glyphs in xrdp_painter.c is not bounds-checked . Since some of this data is controllable by the user, this can result in an out-of-bounds read within the xrdp executable. The vulnerability allows an out-of-bounds read within a potentially privileged process. On non-Debian plat
nvdosv
CVE-2017-6967P4HIGHCVSS 7.3v0.9.12017-03-17
CVE-2017-6967 [HIGH] CWE-287 CVE-2017-6967: xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM sess xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM session modules not being properly initialized, with a potential consequence of incorrect configurations or elevation of privileges, aka a pam_limits.so bypass.
nvdosv
CVE-2023-40184P3MEDIUMCVSS 6.5fixed in 0.9.232023-08-30
CVE-2023-40184 [MEDIUM] CWE-755 CVE-2023-40184: xrdp is an open source remote desktop protocol (RDP) server. In versions prior to 0.9.23 improper ha xrdp is an open source remote desktop protocol (RDP) server. In versions prior to 0.9.23 improper handling of session establishment errors allows bypassing OS-level session restrictions. The `auth_start_session` function can return non-zero (1) value on, e.g., PAM error which may result in in session restrictions such as max concurrent sessions per
nvdosv
CVE-2017-16927P4HIGHCVSS 8.4≤ 0.9.42017-11-23
CVE-2017-16927 [HIGH] CWE-119 CVE-2017-16927: The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9. The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.
nvdosv
CVE-2021-36158P4MEDIUMCVSS 5.9≥ 0, < 0.9.11-r12021-07-05
CVE-2021-36158 [MEDIUM] CVE-2021-36158: In the xrdp package (in branches through 3 In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used.
osv
Neutrinolabs Xrdp vulnerabilities | cvebase