xrdp
neutrinolabs- Software type
- —
- Catalog vulnerabilities
- 37
Severity across 34 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 34 analyzed records
A short verification protects source data and prevents automated AI requests.
As of 09/11/2026, within CyStack's analyzed data, xrdp has 10 security vulnerabilities published in the last 90 days. Of these, 5 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of xrdp and determine which vulnerabilities affect that version.
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-55639xrdp: Out-of-bounds read in GCC Conference Create Request CS_SECURITY processing (xrdp_sec_process_mcs_data_CS_SECURITY) | Exploitation statusNot known exploited | FixYes | Published07/20/2026 | SeverityMedium |
CVE-2026-55626xrdp: No authentication required with Xvnc backend on RHEL 9 | Exploitation statusNot known exploited | FixYes | Published07/20/2026 | SeverityHigh |
CVE-2026-55238xrdp: Malformed Confirm Active capability sets cause out-of-bounds reads | Exploitation statusNot known exploited | FixYes | Published07/20/2026 | SeverityMedium |
CVE-2026-54538xrdp: Pre-auth infinite loop via totalLength=0 in TS_SHARECONTROLHEADER | Exploitation statusNot known exploited | FixYes | Published07/20/2026 | SeverityHigh |
CVE-2026-44978xrdp: Unchecked FIPS padding length in standard RDP Security causes heap out-of-bounds read in HMAC verification | Exploitation statusNot known exploited | FixYes | Published07/20/2026 | SeverityMedium |
CVE-2026-44178xrdp: Channel Data Forwarding Fixed-Size Buffer Overflow | Exploitation statusNot known exploited | FixYes | Published07/20/2026 | SeverityHigh |
CVE-2026-55645xrdp: Out-of-bounds read in Client Control PDU processing (xrdp_rdp_process_data_control) | Exploitation statusNot known exploited | FixYes | Published07/20/2026 | SeverityMedium |
CVE-2026-42218XRDP is vulnerable to a server timing attack, leading to user enumeration | Exploitation statusNot known exploited | FixYes | Published07/20/2026 | SeverityMedium |
CVE-2026-41521xrdp: lib_framebuffer_update Has Integer Overflow Heap Info Leak & ASLR Bypass | Exploitation statusNot known exploited | FixYes | Published07/20/2026 | SeverityHigh |
CVE-2026-41252xrdp: lib_palette_update Heap Buffer Overflow & RCE | Exploitation statusNot known exploited | FixYes | Published07/20/2026 | SeverityCritical |
CVE-2026-35512xrdp: Heap buffer overflow in EGFX channel | Exploitation statusNot known exploited | FixYes | Published04/17/2026 | SeverityHigh |
CVE-2026-33689xrdp: Pre-authentication out-of-bounds reads in channel parsers | Exploitation statusNot known exploited | FixYes | Published04/17/2026 | SeverityHigh |
CVE-2026-33145xrdp: Authenticated RCE via unsanitized AlternateShell execution in xrdp-sesman | Exploitation statusNot known exploited | FixYes | Published04/17/2026 | SeverityMedium |
CVE-2026-32624xrdp: Heap buffer overflow in xrdp_sec_process_logon_info() via incorrect g_strncat length calculation | Exploitation statusNot known exploited | FixYes | Published04/17/2026 | SeverityMedium |
CVE-2026-33516xrdp: Pre-authentication out-of-bounds reads in RDP capability and channel parsers | Exploitation statusNot known exploited | FixYes | Published04/17/2026 | SeverityHigh |
CVE-2026-32623xrdp: Heap buffer overflow in NeutrinoRDP channel reassembly | Exploitation statusNot known exploited | FixYes | Published04/17/2026 | SeverityHigh |
CVE-2026-32105xrdp: RDP MAC signature (dataSignature) never verified on receive — integrity bypass in non-TLS mode | Exploitation statusNot known exploited | FixYes | Published04/17/2026 | SeverityCritical |
CVE-2026-32107xrdp: Fail-open privilege drop in sesexec — child processes may execute as root if setuid fails | Exploitation statusNot known exploited | FixYes | Published04/17/2026 | SeverityHigh |
CVE-2025-68670xrdp improperly checks bounds of domain string length, which leads to Stack-based Buffer Overflow | Exploitation statusNot known exploited | FixNot confirmed | Published01/27/2026 | SeverityCritical |
CVE-2024-39917xrdp allows an ininite number of login attempts | Exploitation statusNot known exploited | FixNot confirmed | Published07/12/2024 | SeverityHigh |
CVE-2023-42822Unchecked access to font glyph info in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Published09/27/2023 | SeverityMedium |
CVE-2023-40184Improper handling of session establishment errors in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Published08/30/2023 | SeverityLow |
CVE-2022-23477Buffer Overflow in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Published12/09/2022 | SeverityCritical |
CVE-2022-23484Integer Overflow in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Published12/09/2022 | SeverityHigh |
CVE-2022-23483Out-of-Bound Read in libxrdp | Exploitation statusNot known exploited | FixNot confirmed | Published12/09/2022 | SeverityHigh |
CVE-2022-23482Out-of-Bound Read in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Published12/09/2022 | SeverityInformational |
CVE-2022-23481Out-of-Bound Read in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Published12/09/2022 | SeverityInformational |
CVE-2022-23480Buffer Overflow in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Published12/09/2022 | SeverityCritical |
CVE-2022-23479Buffer Overflow occurs in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Published12/09/2022 | SeverityCritical |
CVE-2022-23478Out of Bound Write in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Published12/09/2022 | SeverityCritical |
CVE-2022-23468Buffer Overflow in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Published12/09/2022 | SeverityMedium |
CVE-2022-23493Out of Bound Read in xrdp | Exploitation statusNot known exploited | FixNot confirmed | Published12/09/2022 | SeverityCritical |
CVE-2022-23613Privilege escalation on xrdp | Exploitation statusNot known exploited | FixYes | Published02/07/2022 | SeverityHigh |
CVE-2020-4044Local users can perform a buffer overflow attack against the xrdp-sesman service and then impersonate it | Exploitation statusNot confirmed | FixNot confirmed | Published06/30/2020 | SeverityHigh |
CVE-2017-16927CVE-2017-16927 | Exploitation statusNot confirmed | FixNot confirmed | Published11/23/2017 | SeverityUnknown |
CVE-2017-6967CVE-2017-6967 | Exploitation statusNot confirmed | FixNot confirmed | Published03/17/2017 | SeverityUnknown |
CVE-2013-1430CVE-2013-1430 | Exploitation statusNot confirmed | FixNot confirmed | Published12/16/2016 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan