Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

fstec логотип

BDU:2026-15954

3 месяца назад

Уязвимость запроса GCC Conference Create Request сервера XRDP, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2026-55639

3 месяца назад

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Security Data within the Client MCS Connect Initial PDU with GCC Conference Create Request during the connection sequence. During the initial capability and security negotiation phase, the parser fails to perform sufficient length validation for the incoming data block. A remote, unauthenticated attacker could potentially exploit this flaw by sending a specially crafted RDP packet containing malformed data. Due to missing bounds checks, the xrdp process may read a small number of bytes beyond the declared data block boundary, potentially disclosing process memory contents that could be combined with other vulnerabilities. This issue has been fixed in version 0.10.6.1.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-55639

3 месяца назад

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Security Data within the Client MCS Connect Initial PDU with GCC Conference Create Request during the connection sequence. During the initial capability and security negotiation phase, the parser fails to perform sufficient length validation for the incoming data block. A remote, unauthenticated attacker could potentially exploit this flaw by sending a specially crafted RDP packet containing malformed data. Due to missing bounds checks, the xrdp process may read a small number of bytes beyond the declared data block boundary, potentially disclosing process memory contents that could be combined with other vulnerabilities. This issue has been fixed in version 0.10.6.1.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-55639

3 месяца назад

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...

CVSS3: 5.3
EPSS: Низкий
altlinux логотип

ALT-PU-2026-13623

около 2 месяцев назад

ALT-PU-2026-13623: package `xrdp` update to version 0.10.6.1-alt2

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20260818-80-0041

около 2 месяцев назад

Уязвимость xrdp

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20260818-73-0045

около 2 месяцев назад

Уязвимость xrdp

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-15954

Уязвимость запроса GCC Conference Create Request сервера XRDP, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 5.3
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-55639

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Security Data within the Client MCS Connect Initial PDU with GCC Conference Create Request during the connection sequence. During the initial capability and security negotiation phase, the parser fails to perform sufficient length validation for the incoming data block. A remote, unauthenticated attacker could potentially exploit this flaw by sending a specially crafted RDP packet containing malformed data. Due to missing bounds checks, the xrdp process may read a small number of bytes beyond the declared data block boundary, potentially disclosing process memory contents that could be combined with other vulnerabilities. This issue has been fixed in version 0.10.6.1.

CVSS3: 5.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-55639

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Security Data within the Client MCS Connect Initial PDU with GCC Conference Create Request during the connection sequence. During the initial capability and security negotiation phase, the parser fails to perform sufficient length validation for the incoming data block. A remote, unauthenticated attacker could potentially exploit this flaw by sending a specially crafted RDP packet containing malformed data. Due to missing bounds checks, the xrdp process may read a small number of bytes beyond the declared data block boundary, potentially disclosing process memory contents that could be combined with other vulnerabilities. This issue has been fixed in version 0.10.6.1.

CVSS3: 5.3
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-55639

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...

CVSS3: 5.3
0%
Низкий
3 месяца назад
altlinux логотип
ALT-PU-2026-13623

ALT-PU-2026-13623: package `xrdp` update to version 0.10.6.1-alt2

CVSS3: 9.8
около 2 месяцев назад
redos логотип
ROS-20260818-80-0041

Уязвимость xrdp

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
redos логотип
ROS-20260818-73-0045

Уязвимость xrdp

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу