imPC@ndo IT

Citrix vulnerabilities

393 CVE

CVE-2023-24492
Critical 9.6

A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts.

citrix secure_access_client
0.01EPSS
CVE-2013-6942
Medium 6.8

Cross-site request forgery (CSRF) vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to hijack the authentication of unspecified victims via u…

citrix netscaler_application_delivery_controller_firmware
0.01EPSS
CVE-2016-4810
High 7.5

Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenDesktop Delivery Controller via unspecified vectors.

citrix xenapp · citrix xendesktop
0.01EPSS
CVE-2014-1910
Medium 5.8

Citrix ShareFile Mobile and ShareFile Mobile for Tablets before 2.4.4 for Android do not verify X.509 certificates from SSL servers, which allow man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

citrix sharefile_mobile · citrix sharefile_mobile_for_tablets
0.01EPSS
CVE-2011-1898
High 7.4

Xen 4.1 before 4.1.1 and 4.0 before 4.0.2, when using PCI passthrough on Intel VT-d chipsets that do not have interrupt remapping, allows guest OS users to gain host OS privileges by "using DMA to generate MSI interrupts by writing to the interrupt injection r…

citrix xen
0.01EPSS
CVE-2015-3642
Medium 5.9

The TLS and DTLS processing functionality in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices with firmware 9.x before 9.3 Build 68.5, 10.0 through Build 78.6, 10.1 before Build 130.13, 10.1.e before Build 130.1302.e, 10.5 b…

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
0.01EPSS
CVE-2021-22927
High 8.1

A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session.

citrix application_delivery_controller_firmware · citrix gateway · citrix netscaler_gateway
0.01EPSS
CVE-2018-18517
Medium 4.8

Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x before 12.1.49.1 has XSS.

citrix netscaler_gateway_firmware
0.01EPSS
CVE-2018-10650
High 7.8

There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

citrix xenmobile_server
0.01EPSS
CVE-2016-2789
Medium 6.1

Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling Patch 4, and 10.3 before Rolling Patch 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

citrix xenmobile_server
0.01EPSS
CVE-2019-11345
Medium 6.1

Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow XSS.

citrix citrix_sd-wan_center · citrix netscaler_sd-wan_center
0.01EPSS
CVE-2024-5491
High 7.5

Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
0.01EPSS
CVE-2010-4255
Medium 6.1

The fixup_page_fault function in arch/x86/traps.c in Xen 4.0.1 and earlier on 64-bit platforms, when paravirtualization is enabled, does not verify that kernel mode is used to call the handle_gdt_ldt_mapping_fault function, which allows guest OS users to cause…

citrix xen
0.01EPSS
CVE-2024-6236
High 7.5

Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX

citrix netscaler_agent · citrix netscaler_console · citrix netscaler_sdx
0.01EPSS
CVE-2018-10651
Medium 6.1

There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

citrix xenmobile_server
0.01EPSS
CVE-2010-4247
Medium 5.5

The do_block_io_op function in (1) drivers/xen/blkback/blkback.c and (2) drivers/xen/blktap/blktap.c in Xen before 3.4.0 for the Linux kernel 2.6.18, and possibly other versions, allows guest OS users to cause a denial of service (infinite loop and CPU consump…

citrix xen
0.01EPSS
CVE-2010-3699
Low 2.7

The backend driver in Xen 3.x allows guest OS users to cause a denial of service via a kernel thread leak, which prevents the device and guest OS from being shut down or create a zombie domain, causes a hang in zenwatch, or prevents unspecified xm commands fro…

citrix xen
0.01EPSS
CVE-2011-1583
Medium 6.9

Multiple integer overflows in tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allow local users to cause a denial of service and possibly execute arbitrary code via a crafted paravirtualised guest kernel image that triggers (1) a buffer overfl…

citrix xen
0.01EPSS
CVE-2007-6192
Medium 4.3

The web management interface in Citrix NetScaler 8.0 build 47.8 uses weak encryption (XOR of unpadded data) to store credentials within a cookie, which makes it easier for remote attackers to obtain cleartext credentials when a cookie is captured via a known-p…

citrix netscaler
0.01EPSS
CVE-2018-10649
Medium 6.1

There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3.

citrix xenmobile_server
0.01EPSS
CVE-2002-2426
Medium 4.3

Cross-site request forgery (CSRF) vulnerability in Citrix Presentation Server 4.0 and 4.5, MetaFrame Presentation Server 3.0, and Access Essentials 1.0 through 2.0 allows remote attackers to execute arbitrary published applications, and possibly other programs…

citrix access_essentials · citrix metaframe_presentation_server · citrix presentation_server
0.01EPSS
CVE-2022-27506
Low 2.7

Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI

citrix sd-wan_1000_firmware · citrix sd-wan_1100_firmware · citrix sd-wan_110_firmware · citrix sd-wan_2000_firmware · and 10 more
0.01EPSS
CVE-2016-6259
Medium 6.2

Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety c…

citrix xenserver · xen xen
0.01EPSS
CVE-2018-3665
Medium 5.6

System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.

canonical ubuntu_linux · citrix xenserver · debian debian_linux · freebsd freebsd · and 10 more
0.01EPSS
CVE-2014-4700
Medium 4.9

Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user's desktop via unspecified vectors.

citrix xendesktop
0.01EPSS