neutrinolabs
- Products in analyzed data
- 1
- Catalog vulnerabilities
- 37
Severity across 34 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 34 analyzed records
A short verification protects source data and prevents automated AI requests.
As of 09/11/2026, neutrinolabs recorded 10 security vulnerabilities in the last 90 days across 1 products, including 5 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, xrdp had the most security vulnerabilities in the neutrinolabs ecosystem, with 10 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-55639xrdp: Out-of-bounds read in GCC Conference Create Request CS_SECURITY processing (xrdp_sec_process_mcs_data_CS_SECURITY) | Exploitation statusNot known exploited | FixYes | Affected productxrdp | Published07/20/2026 | SeverityMedium |
CVE-2026-55626xrdp: No authentication required with Xvnc backend on RHEL 9 | Exploitation statusNot known exploited | FixYes | Affected productxrdp | Published07/20/2026 | SeverityHigh |
CVE-2026-55238xrdp: Malformed Confirm Active capability sets cause out-of-bounds reads | Exploitation statusNot known exploited | FixYes | Affected productxrdp | Published07/20/2026 | SeverityMedium |
CVE-2026-54538xrdp: Pre-auth infinite loop via totalLength=0 in TS_SHARECONTROLHEADER | Exploitation statusNot known exploited | FixYes | Affected productxrdp | Published07/20/2026 | SeverityHigh |
CVE-2026-44978xrdp: Unchecked FIPS padding length in standard RDP Security causes heap out-of-bounds read in HMAC verification | Exploitation statusNot known exploited | FixYes | Affected productxrdp | Published07/20/2026 | SeverityMedium |
CVE-2026-44178xrdp: Channel Data Forwarding Fixed-Size Buffer Overflow | Exploitation statusNot known exploited | FixYes | Affected productxrdp | Published07/20/2026 | SeverityHigh |
CVE-2026-55645xrdp: Out-of-bounds read in Client Control PDU processing (xrdp_rdp_process_data_control) | Exploitation statusNot known exploited | FixYes | Affected productxrdp | Published07/20/2026 | SeverityMedium |
CVE-2026-42218XRDP is vulnerable to a server timing attack, leading to user enumeration | Exploitation statusNot known exploited | FixYes | Affected productxrdp | Published07/20/2026 | SeverityMedium |
CVE-2026-41521xrdp: lib_framebuffer_update Has Integer Overflow Heap Info Leak & ASLR Bypass | Exploitation statusNot known exploited | FixYes | Affected productxrdp | Published07/20/2026 | SeverityHigh |
CVE-2026-41252xrdp: lib_palette_update Heap Buffer Overflow & RCE | Exploitation statusNot known exploited | FixYes | Affected productxrdp | Published07/20/2026 | SeverityCritical |
CVE-2026-35512xrdp: Heap buffer overflow in EGFX channel | Exploitation statusNot known exploited | FixYes | Affected productxrdp | Published04/17/2026 | SeverityHigh |
CVE-2026-33689xrdp: Pre-authentication out-of-bounds reads in channel parsers | Exploitation statusNot known exploited | FixYes | Affected productxrdp | Published04/17/2026 | SeverityHigh |
CVE-2026-33145xrdp: Authenticated RCE via unsanitized AlternateShell execution in xrdp-sesman | Exploitation statusNot known exploited | FixYes | Affected productxrdp | Published04/17/2026 | SeverityMedium |
CVE-2026-32624xrdp: Heap buffer overflow in xrdp_sec_process_logon_info() via incorrect g_strncat length calculation | Exploitation statusNot known exploited | FixYes | Affected productxrdp | Published04/17/2026 | SeverityMedium |
CVE-2026-33516xrdp: Pre-authentication out-of-bounds reads in RDP capability and channel parsers | Exploitation statusNot known exploited | FixYes | Affected productxrdp | Published04/17/2026 | SeverityHigh |
CVE-2026-32623xrdp: Heap buffer overflow in NeutrinoRDP channel reassembly | Exploitation statusNot known exploited | FixYes | Affected productxrdp | Published04/17/2026 | SeverityHigh |
CVE-2026-32105xrdp: RDP MAC signature (dataSignature) never verified on receive — integrity bypass in non-TLS mode | Exploitation statusNot known exploited | FixYes | Affected productxrdp | Published04/17/2026 | SeverityCritical |
CVE-2026-32107xrdp: Fail-open privilege drop in sesexec — child processes may execute as root if setuid fails | Exploitation statusNot known exploited | FixYes | Affected productxrdp | Published04/17/2026 | SeverityHigh |
CVE-2025-68670xrdp improperly checks bounds of domain string length, which leads to Stack-based Buffer Overflow | Exploitation statusNot known exploited | FixNot confirmed | Affected productxrdp | Published01/27/2026 | SeverityCritical |
CVE-2024-39917xrdp allows an ininite number of login attempts | Exploitation statusNot known exploited | FixNot confirmed | Affected productxrdp | Published07/12/2024 | SeverityHigh |
CVE-2023-42822Unchecked access to font glyph info in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Affected productxrdp | Published09/27/2023 | SeverityMedium |
CVE-2023-40184Improper handling of session establishment errors in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Affected productxrdp | Published08/30/2023 | SeverityLow |
CVE-2022-23477Buffer Overflow in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Affected productxrdp | Published12/09/2022 | SeverityCritical |
CVE-2022-23484Integer Overflow in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Affected productxrdp | Published12/09/2022 | SeverityHigh |
CVE-2022-23483Out-of-Bound Read in libxrdp | Exploitation statusNot known exploited | FixNot confirmed | Affected productxrdp | Published12/09/2022 | SeverityHigh |
CVE-2022-23482Out-of-Bound Read in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Affected productxrdp | Published12/09/2022 | SeverityInformational |
CVE-2022-23481Out-of-Bound Read in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Affected productxrdp | Published12/09/2022 | SeverityInformational |
CVE-2022-23480Buffer Overflow in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Affected productxrdp | Published12/09/2022 | SeverityCritical |
CVE-2022-23479Buffer Overflow occurs in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Affected productxrdp | Published12/09/2022 | SeverityCritical |
CVE-2022-23478Out of Bound Write in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Affected productxrdp | Published12/09/2022 | SeverityCritical |
CVE-2022-23468Buffer Overflow in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Affected productxrdp | Published12/09/2022 | SeverityMedium |
CVE-2022-23493Out of Bound Read in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Affected productxrdp | Published12/09/2022 | SeverityCritical |
CVE-2022-23613Privilege escalation on xrdp | Exploitation statusNot known exploited | FixYes | Affected productxrdp | Published02/07/2022 | SeverityHigh |
CVE-2020-4044Local users can perform a buffer overflow attack against the xrdp-sesman service and then impersonate it | Exploitation statusNot confirmed | FixNot confirmed | Affected productxrdp | Published06/30/2020 | SeverityHigh |
CVE-2017-16927CVE-2017-16927 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published11/23/2017 | SeverityUnknown |
CVE-2017-6967CVE-2017-6967 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published03/17/2017 | SeverityUnknown |
CVE-2013-1430CVE-2013-1430 | Exploitation statusNot confirmed | FixNot confirmed | Affected productxrdp before 0.9.1 | Published12/16/2016 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan