Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 0.77% | — | Neutrinolabs XrdpDebian Linux | 9/12/2022 | 17/6/2026 | xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_sec_process_mcs_data_CS_CORE() function. There are no known workarounds for this issue. Users are advised to upgrade. | |
| Modificada | Crítica (9.1) | 0.77% | — | Neutrinolabs XrdpDebian Linux | 9/12/2022 | 17/6/2026 | xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_caps_process_confirm_active() function. There are no known workarounds for this issue. Users are advised to upgrade. | |
| Modificada | Crítica (9.8) | 0.89% | — | Neutrinolabs XrdpDebian Linux | 9/12/2022 | 17/6/2026 | xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in devredir_proc_client_devlist_announce_req() function. There are no known workarounds for this issue. Users are advised to upgrade. | |
| Modificada | Crítica (9.8) | 0.89% | — | Neutrinolabs XrdpDebian Linux | 9/12/2022 | 17/6/2026 | xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_mm_chan_data_in() function. There are no known workarounds for this issue. Users are advised to upgrade. | |
| Modificada | Crítica (9.8) | 0.84% | — | Neutrinolabs XrdpDebian Linux | 9/12/2022 | 17/6/2026 | xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Write in xrdp_mm_trans_process_drdynvc_channel_open() function. There are no known workarounds for this issue. Users are advised to upgrade. | |
| Modificada | Crítica (9.8) | 0.89% | — | Neutrinolabs XrdpDebian Linux | 9/12/2022 | 17/6/2026 | xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in audin_send_open() function. There are no known workarounds for this issue. Users are advised to upgrade. | |
| Modificada | Crítica (9.8) | 0.80% | — | Neutrinolabs XrdpDebian Linux | 9/12/2022 | 17/6/2026 | xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_login_wnd_create() function. There are no known workarounds for this issue. Users are advised to upgrade. | |
| Modificada | Alta (7.8) | 0.49% | — | Neutrinolabs XrdpFedoraproject Fedora | 7/2/2022 | 17/6/2026 | xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code as root. This vulnerability has been patched in version 0.9.18.1 and… | |
| Modificada | Alta (7.8) | 2.4% | — | Neutrinolabs Xrdp | 30/6/2020 | 17/6/2026 | The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proceed to start their own imposter sesman service listening on port 3350. This will allow them to… | |
| Modificada | Alta (8.4) | 0.41% | — | Neutrinolabs XrdpDebian Linux | 23/11/2017 | 17/6/2026 | The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream. | |
| Modificada | Alta (7.3) | 1.2% | — | Neutrinolabs Xrdp | 17/3/2017 | 17/6/2026 | xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM session modules not being properly initialized, with a potential consequence of incorrect configurations or elevation of privileges, aka a pam_limits.so bypass. | |
| Modificada | Crítica (9.8) | 1.3% | — | Neutrinolabs XrdpDebian Linux | 16/12/2016 | 16/6/2026 | An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted with a known key. | |
| Modificada | Alta (7.5) | 7.3% | 💥 Exploit | Xrdp | 15/1/2009 | 16/6/2026 | The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to have an unknown impact via input data that sets crafted values for certain length variables, leading to a buffer overflow. | |
| Modificada | Alta (7.5) | 3.2% | — | Xrdp | 15/1/2009 | 16/6/2026 | Array index error in the xrdp_bitmap_def_proc function in xrdp/funcs.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via vectors that manipulate the value of the edit_pos structure member. | |
| Modificada | Alta (7.5) | 3.4% | — | Xrdp | 15/1/2009 | 16/6/2026 | Buffer overflow in the xrdp_bitmap_invalidate function in xrdp/xrdp_bitmap.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via a crafted request. |