CVEs (27)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Neutrinolabs2Debian Linux XrdpJun 17, 2026 Dec 9, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in audin_send_open() function. There are no know...Show more |
2Debian Neutrinolabs2Debian Linux XrdpJun 17, 2026 Dec 9, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_login_wnd_create() function. There are n...Show more |
2Fedoraproject Neutrinolabs2Fedora XrdpJun 17, 2026 Feb 7, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a...Show more |
The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proce...Show more |
2Debian Neutrinolabs2Debian Linux XrdpMay 13, 2026 Nov 23, 2017 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow an...Show more |
xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM session modules not being properly initialized, with a potential consequence of incorrect configurations or elevation of pri...Show more |
2Debian Neutrinolabs2Debian Linux XrdpMay 6, 2026 Dec 16, 2016 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext passw...Show more |