imPC@ndo EN

Vulnerabilità Citrix

393 CVE

CVE-2016-5302
Critica 9.8

Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a host by leveraging credentials for an Active Directory account.

citrix xenserver
0.03EPSS
CVE-2007-4017
Alta 7.6

Cross-site request forgery (CSRF) vulnerability in the web-based administration console in Citrix Access Gateway before firmware 4.5.5 allows remote attackers to perform certain configuration changes as administrators.

citrix access_gateway
0.02EPSS
CVE-2002-0503
Media 5.0

Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter.

citrix nfuse
0.02EPSS
CVE-2020-8273
Alta 8.8

Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8.

citrix sd-wan
0.02EPSS
CVE-2017-14602
Alta 7.2

A vulnerability has been identified in the management interface of Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before build 135.18, 10.5 before build 66.9, 10.5e before build 60.7010.e, 11.0 before build 70.16, 11.1 before…

citrix application_delivery_controller_firmware · citrix netscaler_gateway_firmware
0.02EPSS
CVE-2018-6808
Alta 7.5

NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to download arbitrary files on the target system.

citrix netscaler_application_delivery_controller_firmware · citrix netscaler_gateway_firmware
0.02EPSS
CVE-2014-1663
Media 5.0

Unspecified vulnerability in Citrix XenMobile Device Manager server (formerly Zenprise Device Manager server) 8.5, 8.6, and MDM 8.0.1 allows remote attackers to obtain sensitive information via unknown vectors.

citrix xenmobile_device_manager · citrix xenmobile_device_manager_mdm
0.02EPSS
CVE-2000-0244
Alta 10.0

The Citrix ICA (Independent Computing Architecture) protocol uses weak encryption (XOR) for user authentication.

citrix metaframe · citrix winframe
0.02EPSS
CVE-2019-6485
Media 5.9

Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build …

citrix netscaler_application_delivery_controller_firmware · citrix netscaler_gateway_firmware
0.02EPSS
CVE-2009-3759
Alta 8.8

Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to hijack the authentication of administrators for (1) requests that change the password via the username para…

citrix xencenterweb
0.02EPSS
CVE-2015-8555
Alta 8.6

Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains to obtain sensitive information from other domains via unspec…

citrix xenserver · xen xen
0.02EPSS
CVE-2007-4016
Media 6.8

Unspecified vulnerability in the client components in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows attackers to execute arbitrary code via unspecified vectors.

citrix access_gateway
0.02EPSS
CVE-2018-17448
Critica 9.8

An Incorrect Access Control issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

citrix netscaler_sd-wan · citrix sd-wan
0.02EPSS
CVE-2016-6493
Critica 9.8

Citrix XenApp 6.x before 6.5 HRP07 and 7.x before 7.9 and Citrix XenDesktop before 7.9 might allow attackers to weaken an unspecified security mitigation via vectors related to memory permission.

citrix xenapp · citrix xendesktop
0.02EPSS
CVE-2001-1192
Alta 7.5

Citrix Independent Computing Architecture (ICA) Client for Windows 6.1 allows remote malicious web sites to execute arbitrary code via a .ICA file, which is downloaded and automatically executed by the client.

citrix ica_client
0.02EPSS
CVE-2015-7999
Alta 8.1

Multiple SQL injection vulnerabilities in the Administration Web UI servlets in Citrix Command Center before 5.1 Build 36.7 and 5.2 before Build 44.11 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

citrix command_center
0.02EPSS
CVE-2009-2452
Alta 10.0

Multiple unspecified vulnerabilities in Citrix Licensing 11.5 have unknown impact and attack vectors, related to "underlying components of the License Management Console."

citrix licensing
0.02EPSS
CVE-2013-2601
Alta 7.5

The NDVM in Citrix XenClient XT before 2.1.3 and 3.x before 3.1.4 allows remote attackers to execute arbitrary commands by using the UIVM to create a network connection.

citrix xenclient_xt
0.02EPSS
CVE-2007-0011
Media 5.0

The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-dependent attackers to hijack sessions by reading "residual information", including the …

citrix access_gateway
0.02EPSS
CVE-2005-3134
Alta 7.5

Citrix Metaframe Presentation Server 3.0 and 4.0 allows remote attackers to bypass policy restrictions by downloading the launch.ica file and changing the client device name (ClientName).

citrix metaframe
0.02EPSS
CVE-2020-8207
Alta 8.8

Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic updater service is running.

citrix workspace
0.02EPSS
CVE-2002-0301
Media 5.0

Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters.

citrix nfuse
0.02EPSS
CVE-2020-8274
Media 6.5

Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note that a malicious app would need to be installed on the Android …

citrix secure_mail
0.02EPSS
CVE-2015-2829
Alta 7.8

Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.5 Build 53.9 through 55.8 and 10.5.e Build 53-9010.e allow remote attackers to cause a denial of service (reboot) via unspecified vectors.

citrix netscaler_application_delivery_controller_firmware · citrix netscaler_gateway_firmware
0.02EPSS
CVE-2009-2213
Media 6.5

The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Authorization Action option, which might allow remote authenticate…

citrix netscaler_access_gateway · citrix netscaler_access_gateway_firmware
0.02EPSS