Neutrinolabs

Xrdp

27 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.48%
  • Veröffentlicht 17.04.2026 20:21:59
  • Zuletzt bearbeitet 27.04.2026 14:14:42

xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implementation due to insufficient validation of client-controlled size parameters, allowing an out-of-bounds ...

  • EPSS 0.17%
  • Veröffentlicht 17.04.2026 20:16:31
  • Zuletzt bearbeitet 27.04.2026 14:14:26

xrdp is an open source RDP server. Versions through 0.10.5 have an out-of-bounds read vulnerability in the pre-authentication RDP message parsing logic. A remote, unauthenticated attacker can trigger this flaw by sending a specially crafted sequence ...

  • EPSS 0.07%
  • Veröffentlicht 17.04.2026 20:14:14
  • Zuletzt bearbeitet 27.04.2026 14:13:43

xrdp is an open source RDP server. Versions through 0.10.5 allow an authenticated remote user to execute arbitrary commands on the server due to unsafe handling of the AlternateShell parameter in xrdp-sesman. When the AllowAlternateShell setting is e...

  • EPSS 0.1%
  • Veröffentlicht 17.04.2026 19:58:08
  • Zuletzt bearbeitet 27.04.2026 14:16:06

xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in its logon processing. In environments where domain_user_separator is configured in xrdp.ini, an unauthenticated remote attacker can send ...

  • EPSS 0.11%
  • Veröffentlicht 17.04.2026 19:56:11
  • Zuletzt bearbeitet 27.04.2026 14:15:25

xrdp is an open source RDP server. Versions through 0.10.5 contain an out-of-bounds read vulnerability during the RDP capability exchange phase. The issue occurs when memory is accessed before validating the remaining buffer length. A remote, unauthe...

  • EPSS 0.26%
  • Veröffentlicht 17.04.2026 19:43:58
  • Zuletzt bearbeitet 27.04.2026 14:18:48

xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in the NeutrinoRDP module. When proxying RDP sessions from xrdp to another server, the module fails to properly validate the size of reassem...

  • EPSS 0.04%
  • Veröffentlicht 17.04.2026 19:27:39
  • Zuletzt bearbeitet 27.04.2026 14:20:36

xrdp is an open source RDP server. In versions through 0.10.5, xrdp does not implement verification for the Message Authentication Code (MAC) signature of encrypted RDP packets when using the "Classic RDP Security" layer. While the sender correctly g...

  • EPSS 0.02%
  • Veröffentlicht 17.04.2026 19:25:20
  • Zuletzt bearbeitet 27.04.2026 14:19:37

xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle an error during the privilege drop process. This improper privilege management could allow an authenticated local attacker to escal...

Medienbericht
  • EPSS 0.16%
  • Veröffentlicht 27.01.2026 15:52:41
  • Zuletzt bearbeitet 06.02.2026 19:59:50

xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exp...

  • EPSS 0.15%
  • Veröffentlicht 12.07.2024 16:15:04
  • Zuletzt bearbeitet 03.11.2025 20:16:26

xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows attackers to make an infinite number of login attempts. The number of max login attempts is supposed to be limited by a configuration parameter `MaxLog...