Xrdp is an open-source Remote Desktop Protocol server implementation that enables remote desktop access on Linux and Unix systems, representing a narrowly scoped but strategically important component in heterogeneous remote-access environments. The vendor's vulnerability profile centers on its single xrdp product and recurs through input-validation and memory-buffer-handling weakness classes characteristic of network protocol parsers. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xrdp over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5904HIGH The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to have an unknown impact via input data that sets crafted value | Jan 15, 2009 | 7.5 | 31 | NO | YES |
CVE-2008-5903HIGH Array index error in the xrdp_bitmap_def_proc function in xrdp/funcs.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via vectors that manipulate the v | Jan 15, 2009 | 7.5 | 20 | NO | NO |
CVE-2008-5902HIGH Buffer overflow in the xrdp_bitmap_invalidate function in xrdp/xrdp_bitmap.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via a crafted request. | Jan 15, 2009 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xrdp.
Media articles that mention a CVE ID that affects a product developed by Xrdp — matched by CVE ID, not by vendor name.