CVEs we hold for Neutrinolabs
Records whose assigning authority named Neutrinolabs as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-55645xrdp: Out-of-bounds read in Client Control PDU processing (xrdp_rdp_process_data_control)neutrinolabs xrdp
CVE-2026-55639xrdp: Out-of-bounds read in GCC Conference Create Request CS_SECURITY processing (xrdp_sec_process_mcs_data_CS_SECURITY)neutrinolabs xrdp
CVE-2026-55238xrdp: Malformed Confirm Active capability sets cause out-of-bounds readsneutrinolabs xrdp
CVE-2026-54538xrdp: Pre-auth infinite loop via totalLength=0 in TS_SHARECONTROLHEADERneutrinolabs xrdp
CVE-2026-44978xrdp: Unchecked FIPS padding length in standard RDP Security causes heap out-of-bounds read in HMAC verificationneutrinolabs xrdp
CVE-2026-42218XRDP is vulnerable to a server timing attack, leading to user enumerationneutrinolabs xrdp
CVE-2026-41521xrdp: lib_framebuffer_update Has Integer Overflow Heap Info Leak & ASLR Bypassneutrinolabs xrdp
CVE-2026-33516xrdp: Pre-authentication out-of-bounds reads in RDP capability and channel parsersneutrinolabs xrdp
CVE-2026-33145xrdp: Authenticated RCE via unsanitized AlternateShell execution in xrdp-sesmanneutrinolabs xrdp
CVE-2026-32624xrdp: Heap buffer overflow in xrdp_sec_process_logon_info() via incorrect g_strncat length calculationneutrinolabs xrdp
CVE-2026-32107xrdp: Fail-open privilege drop in sesexec — child processes may execute as root if setuid failsneutrinolabs xrdp
CVE-2026-32105xrdp: RDP MAC signature (dataSignature) never verified on receive — integrity bypass in non-TLS modeneutrinolabs xrdp
CVE-2025-68670xrdp improperly checks bounds of domain string length, which leads to Stack-based Buffer Overflowneutrinolabs xrdp
CVE-2020-4044Local users can perform a buffer overflow attack against the xrdp-sesman service and then impersonate itneutrinolabs xrdp
34 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.