imPC@ndo EN

Vulnerabilità Citrix

393 CVE

CVE-2014-2882
Alta 10.0

Unspecified vulnerability in the management GUI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unspecified impact and vectors, related to certificate validation.

citrix netscaler_access_gateway · citrix netscaler_access_gateway_firmware · citrix netscaler_application_delivery_controller · citrix netscaler_application_delivery_controller_firmware
0.01EPSS
CVE-2023-24487
Media 6.3

Arbitrary file read in Citrix ADC and Citrix Gateway 

citrix application_delivery_controller · citrix gateway
0.01EPSS
CVE-2009-2454
Media 4.3

Cross-site scripting (XSS) vulnerability in Citrix Web Interface 4.6, 5.0, and 5.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

citrix web_interface
0.01EPSS
CVE-2008-2299
Media 5.0

Unspecified vulnerability in SecureICA and ICA Basic encryption of Citrix Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 can cause clients to use weaker encryption settings than configured by the administrator, w…

citrix access_essentials · citrix desktop_server · citrix presentation_server
0.01EPSS
CVE-2021-22914
Alta 7.5

Citrix Cloud Connector before 6.31.0.62192 suffers from insecure storage of sensitive information due to sensitive information being stored in the Citrix Cloud Connector installation log files. Such information could be used by an malicious actor to access a C…

citrix cloud_connector
0.01EPSS
CVE-2018-16968
Bassa 3.1

Citrix ShareFile StorageZones Controller before 5.4.2 allows Directory Traversal.

citrix sharefile_storagezones_controller
0.01EPSS
CVE-2016-2072
Media 6.1

The Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, 10.5.e before Build 59.1305.e, and 10.1 allows remote attackers to conduct clickjacking…

citrix netscaler
0.01EPSS
CVE-2013-6940
Media 5.0

Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 logs user credentials, which allows attackers to obtain sensitive information via unspecified vectors.

citrix netscaler_application_delivery_controller_firmware
0.01EPSS
CVE-2008-4405
Alta 7.2

xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM's write access within this tree, which allows guest OS users to cause a denial of service and possibly have unspecifi…

citrix xen
0.01EPSS
CVE-2022-27508
Alta 7.5

Unauthenticated denial of service

citrix application_delivery_controller · citrix gateway
0.01EPSS
CVE-2015-7998
Media 5.0

The administration UI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allows at…

citrix netscaler_application_delivery_controller_firmware · citrix netscaler_gateway_firmware · citrix netscaler_service_delivery_appliance_service_vm
0.01EPSS
CVE-2015-7996
Media 5.0

The Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allow attackers t…

citrix netscaler_application_delivery_controller_firmware · citrix netscaler_gateway_firmware · citrix netscaler_service_delivery_appliance_service_vm
0.01EPSS
CVE-2015-7997
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delive…

citrix netscaler_application_delivery_controller_firmware · citrix netscaler_gateway_firmware · citrix netscaler_service_delivery_appliance_service_vm
0.01EPSS
CVE-2022-27507
Media 6.5

Authenticated denial of service

citrix application_delivery_controller · citrix gateway
0.01EPSS
CVE-2020-8198
Media 6.1

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in Stored Cross-Site Scripting (XSS).

citrix application_delivery_controller_firmware · citrix gateway_firmware · citrix netscaler_gateway_firmware · citrix sd-wan_wanop
0.01EPSS
CVE-2010-4238
Media 5.5

The vbd_create function in Xen 3.1.2, when the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 is used, allows guest OS users to cause a denial of service (host OS panic) via an attempted access to a virtual CD-ROM device through the blkback driver. …

citrix xen
0.01EPSS
CVE-2020-8208
Media 6.1

Improper input validation in Citrix XenMobile Server 10.12 before RP1, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.11 before RP6 and Citrix XenMobile Server before 10.9 RP5 allows Cross-Site Scripting (XSS).

citrix xenmobile_server
0.01EPSS
CVE-2022-27512
Media 5.3

Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM.

citrix application_delivery_management
0.01EPSS
CVE-2021-22919
Alta 7.5

A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, co…

citrix application_delivery_controller_firmware · citrix gateway · citrix netscaler_gateway · citrix sd-wan_wanop
0.01EPSS
CVE-2020-8245
Media 6.1

Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 be…

citrix application_delivery_controller_firmware · citrix gateway · citrix netscaler_gateway
0.01EPSS
CVE-2021-22920
Media 6.5

A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, co…

citrix application_delivery_management · citrix gateway
0.01EPSS
CVE-2016-3710
Alta 8.8

The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.…

canonical ubuntu_linux · citrix xenserver · debian debian_linux · hp helion_openstack · e altri 11
0.01EPSS
CVE-2021-22956
Alta 7.5

An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a temporary disruption of the Management GUI, Nit…

citrix application_delivery_controller_firmware · citrix gateway · citrix sd-wan
0.01EPSS
CVE-2021-22955
Alta 7.5

A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disruption of the Management GUI, Nitro API, an…

citrix application_delivery_controller_firmware · citrix gateway
0.01EPSS
CVE-2023-4967
Alta 8.2

Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
0.01EPSS