Search CVE reports


Toggle filters

11 – 20 of 22 results


CVE-2022-23478

Medium priority

Some fixes available 2 of 3

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Write in xrdp_mm_trans_process_drdynvc_channel_open()...

1 affected package

xrdp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xrdp Not affected Fixed Fixed Not affected Not affected
Show less packages

CVE-2022-23477

Medium priority

Some fixes available 2 of 3

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in audin_send_open() function. There are no known...

1 affected package

xrdp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xrdp Not affected Fixed Fixed Not affected Not affected
Show less packages

CVE-2022-23468

Medium priority

Some fixes available 3 of 4

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_login_wnd_create() function. There are no known...

1 affected package

xrdp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xrdp Not affected Fixed Fixed Fixed Not affected
Show less packages

CVE-2022-23613

Medium priority

Some fixes available 5 of 11

xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman...

1 affected package

xrdp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xrdp Needs evaluation Fixed Fixed Fixed Fixed
Show less packages

CVE-2021-36158

Medium priority
Not affected

In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used.

1 affected package

xrdp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xrdp Not affected Not affected Not affected Not affected
Show less packages

CVE-2020-4044

Medium priority

Some fixes available 4 of 5

The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proceed to...

1 affected package

xrdp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xrdp Not affected Fixed Fixed Fixed
Show less packages

CVE-2017-16927

Medium priority

Some fixes available 2 of 4

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow...

1 affected package

xrdp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xrdp Not affected Not affected Not affected Fixed
Show less packages

CVE-2017-6967

Medium priority

Some fixes available 3 of 6

xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM session modules not being properly initialized, with a potential consequence of incorrect configurations or elevation of privileges,...

1 affected package

xrdp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xrdp Not affected Not affected Not affected Fixed
Show less packages

CVE-2013-1430

Medium priority

Some fixes available 2 of 6

An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES...

1 affected package

xrdp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xrdp Not affected Fixed
Show less packages

CVE-2008-5904

Medium priority
Ignored

The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to have an unknown impact via input data that sets crafted values for certain length variables, leading to a...

1 affected package

xrdp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
xrdp
Show less packages