Vulnerabilidades em neutrinolabs

34 resultados
Análise Vexday

Neutrino Labs apresenta 34 vulnerabilidades conhecidas, com 8 classificadas como críticas (CVSS alto), porém nenhuma está sob exploração ativa registrada. A fraqueza dominante é leitura além dos limites de buffer (CWE-125), padrão típico de falhas de memory safety. O ritmo de descobertas permanece ativo com 10 CVEs publicadas nos últimos 90 dias, indicando risco em evolução que exige monitoramento contínuo, ainda que sem pressão imediata de ataques documentados.

CVE-2026-33689HIGHxrdp: Pre-authentication out-of-bounds reads in channel parsersEPSS 0.5%CVE-2026-33516HIGHxrdp: Pre-authentication out-of-bounds reads in RDP capability and channel parsersEPSS 0.4%CVE-2026-32624MEDIUMxrdp: Heap buffer overflow in xrdp_sec_process_logon_info() via incorrect g_strncat length calculationEPSS 0.4%CVE-2026-41521HIGHxrdp: lib_framebuffer_update Has Integer Overflow Heap Info Leak & ASLR BypassEPSS 0.4%CVE-2026-54538HIGHxrdp: Pre-auth infinite loop via totalLength=0 in TS_SHARECONTROLHEADEREPSS 0.4%CVE-2026-33145MEDIUMxrdp: Authenticated RCE via unsanitized AlternateShell execution in xrdp-sesmanEPSS 0.4%CVE-2026-44978MEDIUMxrdp: Unchecked FIPS padding length in standard RDP Security causes heap out-of-bounds read in HMAC verificationEPSS 0.3%CVE-2026-55238MEDIUMxrdp: Malformed Confirm Active capability sets cause out-of-bounds readsEPSS 0.3%CVE-2026-55645MEDIUMxrdp: Out-of-bounds read in Client Control PDU processing (xrdp_rdp_process_data_control)EPSS 0.3%CVE-2026-55639MEDIUMxrdp: Out-of-bounds read in GCC Conference Create Request CS_SECURITY processing (xrdp_sec_process_mcs_data_CS_SECURITY)EPSS 0.3%CVE-2026-42218MEDIUMXRDP is vulnerable to a server timing attack, leading to user enumerationEPSS 0.3%CVE-2026-32105CRITICALxrdp: RDP MAC signature (dataSignature) never verified on receive — integrity bypass in non-TLS modeEPSS 0.2%CVE-2026-32107HIGHxrdp: Fail-open privilege drop in sesexec — child processes may execute as root if setuid failsEPSS 0.2%CVE-2026-55626HIGHxrdp: No authentication required with Xvnc backend on RHEL 9EPSS 0.1%