Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Rdesktop

First CVE: May 12, 2008Active for: 18 yearsTotal CVEs: 24
66.8
VTI Score
TOP TARGET

Rdesktop is a focused, widely used open-source Remote Desktop Protocol client for Unix and Linux systems, where its narrow product scope belies its presence across many enterprise and embedded deployments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the memory-safety challenges inherent to native protocol parsing and rendering in C. The exposure concentrates entirely within the rdesktop client itself and recurs through a durable pattern of memory-corruption weaknesses—out-of-bounds reads and writes, buffer over-reads, heap-based buffer overflows, and integer overflows—that arise from the parsing of untrusted RDP protocol streams and graphical data. These weakness classes are characteristic of legacy remote-access implementations and render the client vulnerable to network-based remote code execution; defenders should treat rdesktop updates as high-priority and audit instances connected to untrusted networks. Live exploitation activity, severity counts, and exposure breadth are shown alongside this summary.

FAUCET AI Generated
24
Total CVEs
More Total CVEs than 97% of tracked vendors
8.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
8.6
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Rdesktop over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 12, 2008
18 years ago
Most Recent CVE
Oct 30, 2019
2,460 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-1801HIGH
Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Remo
May 12, 20089.339NOYES
CVE-2008-1802HIGH
Buffer overflow in the process_redirect_pdu (rdp.c) function in rdesktop 1.5.0 allows remote attackers to execute arbitrary code via a Remote Desktop Protocol (RDP) redirect reques
May 12, 20089.339NOYES
CVE-2018-20182CRITICAL
rdesktop versions up to and including v1.8.3 contain a Buffer Overflow over the global variables in the function seamless_process_line() that results in memory corruption and proba
Mar 15, 20199.835NONO
CVE-2018-8800CRITICAL
rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corruption and probably even a remote c
Feb 5, 20199.835NONO
CVE-2018-20181CRITICAL
rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function seamless_process() and results in memory corrup
Mar 15, 20199.834NONO
CVE-2018-8797CRITICAL
rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function process_plane() that results in a memory corruption and probably even a remote code ex
Feb 5, 20199.834NONO
CVE-2018-8795CRITICAL
rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in function process_bitmap_updates() and results in a memory cor
Feb 5, 20199.834NONO
CVE-2018-8794CRITICAL
rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in function process_bitmap_updates() and results in a memory corruptio
Feb 5, 20199.834NONO
CVE-2018-8793CRITICAL
rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function cssp_read_tsrequest() that results in a memory corruption and probably even a remote c
Feb 5, 20199.834NONO
CVE-2018-20180CRITICAL
rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsnddbg_process() and results in memory corru
Mar 15, 20199.833NONO
View all 24 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products24 CVEs
54%
42%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network20 (83.3%)
Unknown4 (16.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (83.3%)
High0 (0.0%)
Unknown4 (16.7%)
User Interaction
None20 (83.3%)
Unknown4 (16.7%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None20 (83.3%)
Unknown4 (16.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
8.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Rdesktop.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Rdesktop — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Rdesktop's Products

View all 4 CNAs →

Top CWEs