imPC@ndo EN

Vulnerabilità Citrix

393 CVE

CVE-2017-17382
Media 5.9

Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 might allow remote attackers to decrypt TLS ciphertext data by leveraging a Blei…

citrix application_delivery_controller_firmware · citrix netscaler_gateway_firmware
0.14EPSS
CVE-2024-12284
Alta 8.8

Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.

citrix netscaler_agent · citrix netscaler_console
0.13EPSS
CVE-2015-7705
Critica 9.8

The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.

citrix xenserver · netapp clustered_data_ontap · netapp data_ontap · netapp oncommand_performance_manager · e altri 4
0.12EPSS
CVE-2022-27511
Alta 8.1

Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the d…

citrix application_delivery_management
0.12EPSS
CVE-2020-8271
Critica 9.8

Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8

citrix sd-wan
0.11EPSS
CVE-2018-17445
Critica 9.8

A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

citrix netscaler_sd-wan · citrix sd-wan
0.11EPSS
CVE-2015-7704
Alta 7.5

The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.

citrix xenserver · debian debian_linux · mcafee enterprise_security_manager · netapp clustered_data_ontap · e altri 10
0.11EPSS
CVE-2015-2682
Media 5.0

Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via a direct request to conf/securitydbData.xml.

citrix command_center
0.11EPSS
CVE-2020-8194
Media 6.5

Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows the modification of a file download.

citrix application_delivery_controller_firmware · citrix gateway_firmware · citrix netscaler_gateway_firmware · citrix sd-wan_wanop
0.11EPSS
CVE-2013-3619
Alta 8.1

Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd we…

citrix netscaler_firmware · citrix netscaler_sd-wan_firmware · citrix netscaler_sdx_firmware · supermicro smt_x8_firmware · e altri 1
0.10EPSS
CVE-2025-4365
Alta 7.5

Arbitrary file read in NetScaler Console and NetScaler SDX (SVM)

citrix netscaler_console · citrix netscaler_sdx
0.08EPSS
CVE-2002-0504
Alta 7.5

Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp.

citrix nfuse
0.08EPSS
CVE-2012-4501
Alta 10.0

Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API calls to delete VMs.

apache cloudstack · citrix cloudstack
0.08EPSS
CVE-2022-26151
Alta 7.2

Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.

citrix xenmobile_server
0.08EPSS
CVE-2012-4603
Alta 7.8

Citrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow remote attackers to execute arbitrary code by convincing a target to open a specially crafted file from an SMB or WebDAV fileserver.

citrix receiver · citrix xenapp_online
0.07EPSS
CVE-2025-7776
Critica 9.8

Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) with PCoIP Profile bounded to i…

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
0.07EPSS
CVE-2010-2991
Alta 9.3

The IICAClient interface in the ICAClient library in the ICA Client ActiveX Object (aka ICO) component in Citrix Online Plug-in for Windows for XenApp & XenDesktop before 12.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (me…

citrix online_plug-in_for_windows_for_xenapp_\&_xendesktop
0.07EPSS
CVE-2018-10653
Critica 9.8

There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

citrix xenmobile_server
0.07EPSS
CVE-2013-2758
Media 5.0

Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C uses a hash of a predictable sequence, which makes it easier for remote attackers to guess the console access URL via a brute force attack.

apache cloudstack · citrix cloudplatform
0.06EPSS
CVE-2018-7218
Critica 9.8

The AppFirewall functionality in Citrix NetScaler Application Delivery Controller and NetScaler Gateway 10.5 before Build 68.7, 11.0 before Build 71.24, 11.1 before Build 58.13, and 12.0 before Build 57.24 allows remote attackers to execute arbitrary code via …

citrix application_delivery_controller_firmware · citrix netscaler_gateway_firmware
0.06EPSS
CVE-2021-44520
Alta 8.8

In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.

citrix xenmobile_server
0.06EPSS
CVE-2013-2756
Media 5.0

Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypass the console proxy authentication by leveraging knowledge of the source code.

apache cloudstack · citrix cloudplatform
0.06EPSS
CVE-2012-5161
Alta 9.3

The XML Service interface in Citrix XenApp 6.5 and 6.5 Feature Pack 1 allows remote attackers to execute arbitrary code via unspecified vectors.

citrix xenapp
0.06EPSS
CVE-2015-2841
Media 5.0

Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restrictions via a crafted Content-Type header, as demonstrated by the application/octet-stream and text/xml Content-Types.

citrix netscaler
0.06EPSS
CVE-2014-4947
Alta 10.0

Buffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earlier has unspecified impact and attack vectors.

citrix xenserver
0.05EPSS