imPC@ndo IT

Citrix vulnerabilities

393 CVE

CVE-2005-0822
Low 2.1

Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is not allowed by policy.

citrix metaframe_password_manager
0.00EPSS
CVE-2016-9637
High 7.5

The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS administrators to gain qemu process privileges via vectors involving an out-of-range ioport access.

citrix xenserver
0.00EPSS
CVE-2008-5716
High 7.2

xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) cons…

citrix xen
0.00EPSS
CVE-2012-4606
High 7.8

Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Update 3 contains a Local Privilege Escalation Vulnerability which could allow local users with access to a guest operating system to gain elevated privileges.

citrix xenserver
0.00EPSS
CVE-2012-3516
Medium 6.9

The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4.2 and Citrix XenServer 6.0.2 allows local guest kernels or administrators to cause a denial of service (host crash) and possibly gain privileges via a crafted grant reference that …

citrix xenserver · xen xen
0.00EPSS
CVE-2004-1902
Low 2.1

The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information.

citrix metaframe_password_manager
0.00EPSS
CVE-2008-3485
High 7.2

Untrusted search path vulnerability in Citrix MetaFrame Presentation Server allows local users to gain privileges via a malicious icabar.exe placed in the search path.

citrix metaframe_presentation_server · citrix xp
0.00EPSS
CVE-2016-6276
High 7.8

Citrix Linux Virtual Delivery Agent (aka VDA, formerly Linux Virtual Desktop) before 1.4.0 allows local users to gain root privileges via unspecified vectors.

citrix linux_virtual_delivery_agent
0.00EPSS
CVE-2010-0633
Medium 4.6

Unspecified vulnerability in Citrix XenServer 5.0 Update 3 and earlier, and 5.5, allows local users to bypass authentication and execute unspecified Xen API (XAPI) calls via unknown vectors.

citrix xenserver
0.00EPSS
CVE-2014-2690
Low 2.1

Citrix VDI-in-a-Box 5.3.x before 5.3.6 and 5.4.x before 5.4.3 allows local users to obtain administrator credentials by reading the log.

citrix vdi-in-a-box
0.00EPSS
CVE-2016-5109
Medium 4.3

Citrix Worx Home for iOS before 10.3.6 and XenMobile MDX Toolkit for iOS before 10.3.6 might allow physically proximate attackers to bypass in-application Apple Touch ID authentication via unspecified vectors, related to an application requiring re-authenticat…

citrix worx_home · citrix xenmobile_mdx_toolkit
0.00EPSS
CVE-2011-3262
Low 2.1

tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allows local users to cause a denial of service (management software infinite loop and management domain resource consumption) via unspecified vectors related to "Lack of error checking in the de…

citrix xen
0.00EPSS
CVE-2017-12136
High 7.8

Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling.

citrix xenserver · debian debian_linux · xen xen
0.00EPSS
CVE-2010-2619
Low 1.9

Citrix XenServer 5.0 Update 2 and earlier, and 5.5 Update 1 and earlier, when using a pvops kernel, allows guest users to cause a denial of service in the host via unspecified vectors that trigger "incorrectly set flags."

citrix xenserver
0.00EPSS
CVE-2023-24490
Medium 6.3

Users with only access to launch VDA applications can launch an unauthorized desktop

citrix linux_virtual_delivery_agent · citrix virtual_apps_and_desktops
0.00EPSS
CVE-2008-5107
Low 1.9

The installation process for Citrix Presentation Server 4.5 and Desktop Server 1.0, when MSI logging is enabled, stores database credentials in MSI log files, which allows local users to obtain these credentials by reading the log files.

citrix desktop_server · citrix presentation_server
0.00EPSS
CVE-2016-9381
High 7.5

Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double fetch" vulnerability.

citrix xenserver · qemu qemu
0.00EPSS
CVE-2008-4676
Medium 6.8

Unspecified vulnerability in Citrix XenApp (formerly Presentation Server) 4.5 Feature Pack 1 and earlier, Presentation Server 4.0, and Access Essentials 1.0, 1.5, and 2.0 allows local users to gain privileges via unknown attack vectors related to creating an u…

citrix access_essentials · citrix presentation_server · citrix xenapp
0.00EPSS
CVE-2008-6561
Low 1.9

Citrix Presentation Server Client for Windows before 10.200 does not clear "credential information" from process memory in unspecified circumstances, which might allow local users to gain privileges.

citrix presentation_server_client
0.00EPSS
CVE-2022-27513
High 8.3

Remote desktop takeover via phishing

citrix application_delivery_controller_firmware · citrix gateway
0.00EPSS
CVE-2023-24483
High 7.8

A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA.

citrix virtual_apps_and_desktops
0.00EPSS
CVE-2023-24484
Medium 5.5

A malicious user can cause log files to be written to a directory that they do not have permission to write to.

citrix workspace
0.00EPSS
CVE-2021-22928
High 7.8

A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix Profile Management WMI Plugin installed to escalate their privilege level on tha…

citrix virtual_apps_and_desktops · citrix xenapp · citrix xendesktop
0.00EPSS
CVE-2025-6759
High 7.8

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Windows Virtual Delivery Agent for CVAD and Citrix DaaS

citrix virtual_apps_and_desktops
0.00EPSS
CVE-2024-7889
High 7.3

Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

citrix workspace
0.00EPSS