imPC@ndo EN

Vulnerabilità Citrix

393 CVE

CVE-2008-0356
Alta 10.0

Buffer overflow in the Independent Management Architecture (IMA) service in Citrix Presentation Server (MetaFrame Presentation Server) 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 allows remote attackers to execute arbitrary code …

citrix access_essentials · citrix desktop_server · citrix metaframe_presentation_server · citrix presentation_server
0.73EPSS
CVE-2019-10883
Critica 9.8

Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection.

citrix citrix_sd-wan_center · citrix netscaler_sd-wan_center
0.65EPSS
CVE-2011-2882
Alta 9.3

Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 allows remote attackers to execute arbitrary code via crafted HTTP h…

citrix access_gateway
0.56EPSS
CVE-2018-14007
Critica 9.8

Citrix XenServer 7.1 and newer allows Directory Traversal.

citrix xenserver
0.56EPSS
CVE-2019-12992
Alta 8.8

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6).

citrix netscaler_sd-wan · citrix sd-wan
0.49EPSS
CVE-2020-8209
Alta 7.5

Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.

citrix xenmobile_server
0.49EPSS
CVE-2023-6184
Media 5.0

Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting

citrix virtual_apps_and_desktops
0.47EPSS
CVE-2019-12988
Critica 9.8

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6).

citrix netscaler_sd-wan · citrix sd-wan
0.43EPSS
CVE-2019-12987
Critica 9.8

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6).

citrix netscaler_sd-wan · citrix sd-wan
0.43EPSS
CVE-2019-12986
Critica 9.8

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6).

citrix netscaler_sd-wan · citrix sd-wan
0.40EPSS
CVE-2019-12985
Critica 9.8

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6).

citrix netscaler_sd-wan · citrix sd-wan
0.40EPSS
CVE-2019-12990
Critica 9.8

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal.

citrix netscaler_sd-wan · citrix sd-wan
0.39EPSS
CVE-2012-0217
Alta 7.2

The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3;…

citrix xenserver · freebsd freebsd · illumos illumos · joyent smartos · e altri 7
0.37EPSS
CVE-2006-6334
Media 6.8

Heap-based buffer overflow in the SendChannelData function in wfica.ocx in Citrix Presentation Server Client before 9.230 for Windows allows remote malicious web sites to execute arbitrary code via a DataSize parameter that is less than the length of the Data …

citrix presentation_server_client
0.35EPSS
CVE-2010-4566
Alta 9.3

The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers…

citrix access_gateway
0.28EPSS
CVE-2020-8982
Alta 7.5

An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020. RCE and file access is granted to everything hosted by ShareFile, be …

citrix sharefile_storagezones_controller
0.27EPSS
CVE-2020-8191
Media 6.1

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS).

citrix application_delivery_controller_firmware · citrix gateway_firmware · citrix netscaler_gateway_firmware · citrix sd-wan_wanop
0.26EPSS
CVE-2024-6235
Alta 8.8

Sensitive information disclosure in NetScaler Console

citrix netscaler_console
0.21EPSS
CVE-2018-8897
Alta 7.8

A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferr…

apple mac_os_x · canonical ubuntu_linux · citrix xenserver · debian debian_linux · e altri 7
0.19EPSS
CVE-2014-7140
Alta 7.5

Unspecified vulnerability in the management interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.x before 10.1-129.11 and 10.5 before 10.5-50.10 allows remote attackers to execute arbitrary code via unknown vectors.

citrix netscaler_application_delivery_controller_firmware
0.16EPSS
CVE-2005-3652
Alta 7.5

Heap-based buffer overflow in Citrix Program Neighborhood client 9.0 and earlier allows remote attackers to execute arbitrary code via a long name value in an Application Set response.

citrix ica_program_neighborhood_client
0.16EPSS
CVE-2026-8451
Alta 7.5

Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
0.16EPSS
CVE-2011-2592
Alta 9.3

Heap-based buffer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9.x before 9.3-57.5 and 10.0 before 10.0-69.4 allows remote attackers to execute arbitrary code via a …

citrix access_gateway_plug-in
0.15EPSS
CVE-2020-7473
Alta 7.5

In certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, allow unauthenticated attackers to access the documents and folders of ShareFile users. NOTE: unlike …

citrix sharefile_storagezones_controller
0.14EPSS
CVE-2007-0444
Alta 7.2

Stack-based buffer overflow in the print provider library (cpprov.dll) in Citrix Presentation Server 4.0, MetaFrame Presentation Server 3.0, and MetaFrame XP 1.0 allows local users and remote attackers to execute arbitrary code via long arguments to the (1) En…

citrix metaframe · citrix metaframe_presentation_server
0.14EPSS