imPC@ndo IT

Citrix vulnerabilities

393 CVE

CVE-2020-10111
High 7.5

Citrix Gateway 11.1, 12.0, and 12.1 has an Inconsistent Interpretation of HTTP Requests. NOTE: Citrix disputes the reported behavior as not a security issue. Citrix ADC only caches HTTP/1.1 traffic for performance optimization

citrix gateway_firmware
0.02EPSS
CVE-2019-7217
High 7.5

Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on different server responses using the request to check the otp code. No authentication is required.

citrix sharefile
0.02EPSS
CVE-2015-2839
Medium 4.3

The Nitro API in Citrix NetScaler before 10.5 build 52.3nc uses an incorrect Content-Type when returning an error message, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the file_name JSON member in params/xen_hotfix/0 to nitro…

citrix netscaler
0.02EPSS
CVE-2008-3253
Medium 4.3

Cross-site scripting (XSS) vulnerability in the XenAPI HTTP interfaces in Citrix XenServer Express, Standard, and Enterprise Edition 4.1.0; Citrix XenServer Dell Edition (Express and Enterprise) 4.1.0; and HP integrated Citrix XenServer (Select and Enterprise)…

citrix xenserver
0.02EPSS
CVE-2018-17446
Critical 9.8

A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

citrix netscaler_sd-wan · citrix sd-wan
0.02EPSS
CVE-2020-8187
High 7.5

Improper input validation in Citrix ADC and Citrix Gateway versions before 11.1-63.9 and 12.0-62.10 allows unauthenticated users to perform a denial of service attack.

citrix application_delivery_controller_firmware · citrix netscaler_gateway_firmware
0.02EPSS
CVE-2018-17447
High 7.5

An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

citrix netscaler_sd-wan · citrix sd-wan
0.02EPSS
CVE-2015-2840
Medium 4.3

Cross-site scripting (XSS) vulnerability in help/rt/large_search.html in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to inject arbitrary web script or HTML via the searchQuery parameter.

citrix netscaler
0.02EPSS
CVE-2014-3798
Medium 6.5

The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted Ethernet frame.

citrix xenserver
0.02EPSS
CVE-2016-9680
High 7.5

Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive information from kernel memory via unspecified vectors.

citrix provisioning_services
0.02EPSS
CVE-2014-4948
Medium 6.4

Unspecified vulnerability in Citrix XenServer 6.2 Service Pack 1 and earlier allows attackers to cause a denial of service and obtain sensitive information by modifying the guest virtual hard disk (VHD).

citrix xenserver
0.02EPSS
CVE-2020-8275
Medium 4.3

Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a …

citrix secure_mail
0.02EPSS
CVE-2014-2881
High 10.0

Unspecified vulnerability in the Diffie-Hellman key agreement implementation in the management GUI Java applet in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unknown impact and ve…

citrix netscaler_access_gateway · citrix netscaler_access_gateway_firmware · citrix netscaler_application_delivery_controller · citrix netscaler_application_delivery_controller_firmware
0.02EPSS
CVE-2016-9028
High 8.8

Unauthorized redirect vulnerability in Citrix NetScaler ADC before 10.1 135.8, 10.5 61.11, 11.0 65.31/65.35F and 11.1 47.14 allows a remote attacker to steal session cookies of a legitimate AAA user via manipulation of Host header.

citrix netscaler_application_delivery_controller_firmware
0.02EPSS
CVE-2020-8197
High 8.8

Privilege escalation vulnerability on Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows a low privileged user with management access to execute arbitrary commands.

citrix application_delivery_controller_firmware · citrix gateway_firmware · citrix netscaler_gateway_firmware
0.02EPSS
CVE-2017-9231
High 7.5

XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via unspecified vectors.

citrix xenmobile_server
0.02EPSS
CVE-2016-9111
Medium 6.8

Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication requirement by leveraging physical access to a VDI for temporary disconnection of a LAN cable. NOTE: as of 20161208, the vendor could not rep…

citrix receiver_desktop
0.02EPSS
CVE-2012-6314
Medium 5.0

Citrix XenDesktop Virtual Desktop Agent (VDA) 5.6.x before 5.6.200, when making changes to the server-side policy that control USB redirection, does not propagate changes to the VDA, which allows authenticated users to retain access to the USB device.

citrix xendesktop
0.02EPSS
CVE-2007-3625
Medium 5.0

The Program Neighborhood Agent in Citrix Presentation Server Clients for 32-bit Windows before 10.100 allows remote attackers to cause a denial of service (agent exit) via a certain request that uses content redirection and a long pathname.

citrix metaframe_presentation_server
0.02EPSS
CVE-2010-4515
Medium 4.3

Cross-site scripting (XSS) vulnerability in Citrix Web Interface 5.0, 5.1, and 5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-6477 and CVE-2009-2454.

citrix web_interface
0.02EPSS
CVE-2016-6273
High 7.5

The lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) before 2015 SP5 and 2016 before R1 SP1, as used by Citrix License Server for Windows before 11.14.0.1 and Citrix License Server VPX before 11.14.0.1, allows remote attackers to cause…

citrix license_server · citrix license_server_vpx
0.02EPSS
CVE-2008-6830
Medium 4.0

The disconnection feature in Citrix Web Interface 5.0 and 5.0.1 for Java Application Servers does not properly terminate a user's web interface session, which allows attackers with access to the same browser instance to gain access to the user's Web Interface …

citrix web_interface
0.02EPSS
CVE-2009-3757
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to config/edituser.php; (2) location, (3) sessi…

citrix xencenterweb
0.02EPSS
CVE-2014-4347
Medium 5.0

Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) before 9.3-62.4 and 10.x before 10.1-126.12 allows attackers to obtain sensitive information via vectors related to a cookie.

citrix netscaler_access_gateway · citrix netscaler_access_gateway_firmware · citrix netscaler_application_delivery_controller · citrix netscaler_application_delivery_controller_firmware
0.02EPSS
CVE-2009-2214
Medium 5.0

The Secure Gateway service in Citrix Secure Gateway 3.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an unspecified request.

citrix secure_gateway
0.02EPSS