VYPR

Xrdp

by Xrdp

Source repositories

CVEs (28)

  • CVE-2025-68670CriJan 27, 2026
    risk 0.00cvss 9.1epss 0.01

    xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability…

  • CVE-2023-42822MedSep 27, 2023
    risk 0.00cvss 4.6epss 0.01

    xrdp is an open source remote desktop protocol server. Access to the font glyphs in xrdp_painter.c is not bounds-checked . Since some of this data is controllable by the user, this can result in an out-of-bounds read within the xrdp executable. The vulnerability allows an…

  • CVE-2023-40184LowAug 30, 2023
    risk 0.00cvss 2.6epss 0.01

    xrdp is an open source remote desktop protocol (RDP) server. In versions prior to 0.9.23 improper handling of session establishment errors allows bypassing OS-level session restrictions. The `auth_start_session` function can return non-zero (1) value on, e.g., PAM error which…

  • CVE-2022-23482NonDec 9, 2022
    risk 0.00cvss 0.0epss 0.01

    xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_sec_process_mcs_data_CS_CORE() function. There are no known workarounds for this issue. Users are…

  • CVE-2022-23481NonDec 9, 2022
    risk 0.00cvss 0.0epss 0.01

    xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_caps_process_confirm_active() function. There are no known workarounds for this issue. Users are…

  • CVE-2022-23613HigFeb 7, 2022
    risk 0.00cvss 7.8epss 0.00

    xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code as root. This vulnerability…

  • CVE-2008-5903Jan 15, 2009
    risk 0.00cvss epss 0.03

    Array index error in the xrdp_bitmap_def_proc function in xrdp/funcs.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via vectors that manipulate the value of the edit_pos structure member.

  • CVE-2008-5902Jan 15, 2009
    risk 0.00cvss epss 0.03

    Buffer overflow in the xrdp_bitmap_invalidate function in xrdp/xrdp_bitmap.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via a crafted request.

Page 2 of 2