citrix CVE Vulnerabilities & Metrics

Focus on citrix vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About citrix Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with citrix. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total citrix CVEs: 223
Earliest CVE date: 29 Mar 2000, 05:00 UTC
Latest CVE date: 11 Sep 2024, 23:15 UTC

Latest CVE reference: CVE-2024-7890

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 6

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -60.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -60.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical citrix CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.62

Max CVSS: 10.0

Critical CVEs (≥9): 58

CVSS Range vs. Count

Range Count
0.0-3.9 55
4.0-6.9 183
7.0-8.9 62
9.0-10.0 58

CVSS Distribution Chart

Top 5 Highest CVSS citrix CVEs

These are the five CVEs with the highest CVSS scores for citrix, sorted by severity first and recency.

All CVEs for citrix

CVE-2024-7890 citrix vulnerability CVSS: 0 11 Sep 2024, 23:15 UTC

Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

CVE-2024-7889 citrix vulnerability CVSS: 0 11 Sep 2024, 23:15 UTC

Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

CVE-2024-42423 citrix vulnerability CVSS: 0 10 Sep 2024, 15:15 UTC

Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and perform unauthorized actions leading to information disclosure and tampering.

CVE-2024-6148 citrix vulnerability CVSS: 0 10 Jul 2024, 21:15 UTC

Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5

CVE-2024-5661 citrix vulnerability CVSS: 0 13 Jun 2024, 06:15 UTC

An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may allow a malicious administrator of a guest VM to cause the host to become slow and/or unresponsive.

CVE-2024-3661 citrix vulnerability CVSS: 0 06 May 2024, 19:15 UTC

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

CVE-2023-6184 citrix vulnerability CVSS: 0 18 Jan 2024, 01:15 UTC

Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting

CVE-2023-6549 citrix vulnerability CVSS: 0 17 Jan 2024, 21:15 UTC

Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read

CVE-2023-6548 citrix vulnerability CVSS: 0 17 Jan 2024, 20:15 UTC

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.

CVE-2023-4967 citrix vulnerability CVSS: 0 27 Oct 2023, 19:15 UTC

Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server

CVE-2023-4966 citrix vulnerability CVSS: 0 10 Oct 2023, 14:15 UTC

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

CVE-2023-3467 citrix vulnerability CVSS: 0 19 Jul 2023, 19:15 UTC

Privilege Escalation to root administrator (nsroot)

CVE-2023-3466 citrix vulnerability CVSS: 0 19 Jul 2023, 19:15 UTC

Reflected Cross-Site Scripting (XSS)

CVE-2023-3519 citrix vulnerability CVSS: 0 19 Jul 2023, 18:15 UTC

Unauthenticated remote code execution

CVE-2023-24492 citrix vulnerability CVSS: 0 11 Jul 2023, 22:15 UTC

A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts.

CVE-2023-24491 citrix vulnerability CVSS: 0 11 Jul 2023, 22:15 UTC

A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate their local privileges to that of NT AUTHORITY\SYSTEM.

CVE-2023-24490 citrix vulnerability CVSS: 0 10 Jul 2023, 22:15 UTC

Users with only access to launch VDA applications can launch an unauthorized desktop

CVE-2023-24489 citrix vulnerability CVSS: 0 10 Jul 2023, 22:15 UTC

A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.

CVE-2023-24488 citrix vulnerability CVSS: 0 10 Jul 2023, 21:15 UTC

Cross site scripting vulnerability in Citrix ADC and Citrix Gateway  in allows and attacker to perform cross site scripting

CVE-2023-24487 citrix vulnerability CVSS: 0 10 Jul 2023, 21:15 UTC

Arbitrary file read in Citrix ADC and Citrix Gateway 

CVE-2023-24486 citrix vulnerability CVSS: 0 10 Jul 2023, 21:15 UTC

A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is launched.

CVE-2023-24485 citrix vulnerability CVSS: 0 16 Feb 2023, 18:15 UTC

Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.

CVE-2023-24484 citrix vulnerability CVSS: 0 16 Feb 2023, 18:15 UTC

A malicious user can cause log files to be written to a directory that they do not have permission to write to.

CVE-2023-24483 citrix vulnerability CVSS: 0 16 Feb 2023, 18:15 UTC

A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA.

CVE-2022-27508 citrix vulnerability CVSS: 0 26 Jan 2023, 21:15 UTC

Unauthenticated denial of service

CVE-2022-27507 citrix vulnerability CVSS: 0 26 Jan 2023, 21:15 UTC

Authenticated denial of service

CVE-2019-18177 citrix vulnerability CVSS: 0 26 Dec 2022, 21:15 UTC

In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update.

CVE-2022-27518 citrix vulnerability CVSS: 0 13 Dec 2022, 17:15 UTC

Unauthenticated remote arbitrary code execution

CVE-2022-27516 citrix vulnerability CVSS: 0 08 Nov 2022, 22:15 UTC

User login brute force protection functionality bypass

CVE-2022-27513 citrix vulnerability CVSS: 0 08 Nov 2022, 22:15 UTC

Remote desktop takeover via phishing

CVE-2022-27510 citrix vulnerability CVSS: 0 08 Nov 2022, 22:15 UTC

Unauthorized access to Gateway user capabilities

CVE-2022-27509 citrix vulnerability CVSS: 0 28 Jul 2022, 14:15 UTC

Unauthenticated redirection to a malicious website

CVE-2022-27512 citrix vulnerability CVSS: 5.0 16 Jun 2022, 19:15 UTC

Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM.

CVE-2022-27511 citrix vulnerability CVSS: 7.8 16 Jun 2022, 19:15 UTC

Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the device has rebooted.

CVE-2022-21827 citrix vulnerability CVSS: 6.6 26 May 2022, 17:15 UTC

An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as SYSTEM.

CVE-2021-44519 citrix vulnerability CVSS: 6.0 19 Apr 2022, 16:17 UTC

In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.

CVE-2022-27506 citrix vulnerability CVSS: 6.8 13 Apr 2022, 18:15 UTC

Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI

CVE-2022-27505 citrix vulnerability CVSS: 4.3 13 Apr 2022, 18:15 UTC

Reflected cross site scripting (XSS)

CVE-2022-27503 citrix vulnerability CVSS: 2.6 13 Apr 2022, 18:15 UTC

Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9

CVE-2022-26151 citrix vulnerability CVSS: 9.0 13 Apr 2022, 00:15 UTC

Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.

CVE-2021-44520 citrix vulnerability CVSS: 9.0 13 Apr 2022, 00:15 UTC

In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.

CVE-2022-26355 citrix vulnerability CVSS: 1.9 10 Mar 2022, 17:47 UTC

Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key Storage Provider (MSKSP). This issue only occurs if PowerShell was used when configuring FAS to store the registration authority certificate’s private key in the TPM. It does not occur if the TPM was not selected for use or if the FAS administration console was used for configuration.

CVE-2022-21825 citrix vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation.

CVE-2021-22956 citrix vulnerability CVSS: 4.3 07 Dec 2021, 14:15 UTC

An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.

CVE-2021-22955 citrix vulnerability CVSS: 4.3 07 Dec 2021, 14:15 UTC

A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.

CVE-2021-22941 citrix vulnerability CVSS: 10.0 23 Sep 2021, 13:15 UTC

Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.

CVE-2021-22932 citrix vulnerability CVSS: 5.0 16 Aug 2021, 19:15 UTC

An issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones controller which causes the ShareFile file encryption option to become disabled if it had previously been enabled. Customers are only affected by this issue if they previously selected “Enable Encryption” in the ShareFile configuration page and did not re-select this setting after running the CTX269106 mitigation tool. ShareFile customers who have not run the CTX269106 mitigation tool or who re-selected “Enable Encryption” immediately after running the tool are unaffected by this issue.

CVE-2021-22928 citrix vulnerability CVSS: 7.2 05 Aug 2021, 21:15 UTC

A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix Profile Management WMI Plugin installed to escalate their privilege level on that Windows VDA to SYSTEM.

CVE-2021-22927 citrix vulnerability CVSS: 5.8 05 Aug 2021, 21:15 UTC

A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session.

CVE-2021-22920 citrix vulnerability CVSS: 4.3 05 Aug 2021, 21:15 UTC

A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to a phishing attack through a SAML authentication hijack to steal a valid user session.

CVE-2021-22919 citrix vulnerability CVSS: 5.0 05 Aug 2021, 21:15 UTC

A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to the limited available disk space on the appliances being fully consumed.

CVE-2021-22914 citrix vulnerability CVSS: 5.0 16 Jun 2021, 14:15 UTC

Citrix Cloud Connector before 6.31.0.62192 suffers from insecure storage of sensitive information due to sensitive information being stored in the Citrix Cloud Connector installation log files. Such information could be used by an malicious actor to access a Citrix Cloud environment. This issue affects all versions of Citrix Cloud Connector that were installed by passing secure client parameters for installation via the command line. The issue does not affect Citrix Cloud Connector if it was installed using the interactive installer or where a parameter file was used with the command-line installer.

CVE-2020-8300 citrix vulnerability CVSS: 4.3 16 Jun 2021, 14:15 UTC

Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a SAML SP or a SAML IdP for this to be possible.

CVE-2020-8299 citrix vulnerability CVSS: 3.3 16 Jun 2021, 14:15 UTC

Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a network-based denial-of-service from within the same Layer 2 network segment. Note that the attacker must be in the same Layer 2 network segment as the vulnerable appliance.

CVE-2021-22907 citrix vulnerability CVSS: 7.2 27 May 2021, 12:15 UTC

An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalation in CR versions prior to 2105 and 1912 LTSR prior to CU4.

CVE-2021-22891 citrix vulnerability CVSS: 7.5 27 May 2021, 12:15 UTC

A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.10.1 and 5.11.18 may allow unauthenticated remote compromise of the Storage Zones Controller.

CVE-2020-8275 citrix vulnerability CVSS: 4.3 06 Jan 2021, 21:15 UTC

Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.

CVE-2020-8274 citrix vulnerability CVSS: 4.3 06 Jan 2021, 21:15 UTC

Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.

CVE-2020-8283 citrix vulnerability CVSS: 9.0 14 Dec 2020, 20:15 UTC

An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9.

CVE-2020-8258 citrix vulnerability CVSS: 5.0 14 Dec 2020, 20:15 UTC

Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, allows an attacker to modify arbitrary files.

CVE-2020-8257 citrix vulnerability CVSS: 7.5 14 Dec 2020, 20:15 UTC

Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, lead to privilege escalation attacks

CVE-2020-8273 citrix vulnerability CVSS: 9.0 16 Nov 2020, 01:15 UTC

Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8.

CVE-2020-8272 citrix vulnerability CVSS: 5.0 16 Nov 2020, 01:15 UTC

Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8

CVE-2020-8271 citrix vulnerability CVSS: 10.0 16 Nov 2020, 01:15 UTC

Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8

CVE-2020-8270 citrix vulnerability CVSS: 9.0 16 Nov 2020, 01:15 UTC

An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285871 and CTX285872, 7.15 LTSR CU6 hotfix CTX285341 and CTX285342

CVE-2020-8269 citrix vulnerability CVSS: 9.0 16 Nov 2020, 01:15 UTC

An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9

CVE-2020-8253 citrix vulnerability CVSS: 5.0 18 Sep 2020, 21:15 UTC

Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 leads to the ability to access sensitive files.

CVE-2020-8247 citrix vulnerability CVSS: 6.5 18 Sep 2020, 21:15 UTC

Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0 before 11.0.3f, Citrix SD-WAN WANOP 10.2 before 10.2.7b are vulnerable to escalation of privileges on the management interface.

CVE-2020-8246 citrix vulnerability CVSS: 5.0 18 Sep 2020, 21:15 UTC

Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0 before 11.0.3f, Citrix SD-WAN WANOP 10.2 before 10.2.7b are vulnerable to a denial of service attack originating from the management network.

CVE-2020-8245 citrix vulnerability CVSS: 4.3 18 Sep 2020, 21:15 UTC

Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0 before 11.0.3f, Citrix SD-WAN WANOP 10.2 before 10.2.7b leads to an HTML Injection attack against the SSL VPN web portal.

CVE-2020-8200 citrix vulnerability CVSS: 4.0 18 Sep 2020, 21:15 UTC

Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.

CVE-2020-8212 citrix vulnerability CVSS: 7.5 17 Aug 2020, 16:15 UTC

Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows access to privileged functionality.

CVE-2020-8211 citrix vulnerability CVSS: 7.5 17 Aug 2020, 16:15 UTC

Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows SQL Injection.

CVE-2020-8210 citrix vulnerability CVSS: 5.0 17 Aug 2020, 16:15 UTC

Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 discloses credentials of a service account.

CVE-2020-8209 citrix vulnerability CVSS: 5.0 17 Aug 2020, 16:15 UTC

Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.

CVE-2020-8208 citrix vulnerability CVSS: 4.3 17 Aug 2020, 16:15 UTC

Improper input validation in Citrix XenMobile Server 10.12 before RP1, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.11 before RP6 and Citrix XenMobile Server before 10.9 RP5 allows Cross-Site Scripting (XSS).

CVE-2020-8207 citrix vulnerability CVSS: 6.0 24 Jul 2020, 22:15 UTC

Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic updater service is running.

CVE-2020-8199 citrix vulnerability CVSS: 4.6 10 Jul 2020, 16:15 UTC

Improper access control in Citrix ADC Gateway Linux client versions before 1.0.0.137 results in local privilege escalation to root.

CVE-2020-8198 citrix vulnerability CVSS: 4.3 10 Jul 2020, 16:15 UTC

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in Stored Cross-Site Scripting (XSS).

CVE-2020-8197 citrix vulnerability CVSS: 6.5 10 Jul 2020, 16:15 UTC

Privilege escalation vulnerability on Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows a low privileged user with management access to execute arbitrary commands.

CVE-2020-8196 citrix vulnerability CVSS: 4.0 10 Jul 2020, 16:15 UTC

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.

CVE-2020-8195 citrix vulnerability CVSS: 4.0 10 Jul 2020, 16:15 UTC

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.

CVE-2020-8194 citrix vulnerability CVSS: 4.3 10 Jul 2020, 16:15 UTC

Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows the modification of a file download.

CVE-2020-8193 citrix vulnerability CVSS: 5.0 10 Jul 2020, 16:15 UTC

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.

CVE-2020-8191 citrix vulnerability CVSS: 4.3 10 Jul 2020, 16:15 UTC

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS).

CVE-2020-8190 citrix vulnerability CVSS: 6.0 10 Jul 2020, 16:15 UTC

Incorrect file permissions in Citrix ADC and Citrix Gateway before versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows privilege escalation.

CVE-2020-8187 citrix vulnerability CVSS: 5.0 10 Jul 2020, 16:15 UTC

Improper input validation in Citrix ADC and Citrix Gateway versions before 11.1-63.9 and 12.0-62.10 allows unauthenticated users to perform a denial of service attack.

CVE-2020-13998 citrix vulnerability CVSS: 4.3 11 Jun 2020, 02:15 UTC

Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA error page only occurs after a valid username is entered. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2020-13885 citrix vulnerability CVSS: 7.2 08 Jun 2020, 19:15 UTC

Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during the uninstallation of the application.

CVE-2020-13884 citrix vulnerability CVSS: 7.2 08 Jun 2020, 19:15 UTC

Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges during the uninstallation of the application.

CVE-2020-8983 citrix vulnerability CVSS: 5.0 07 May 2020, 14:15 UTC

An arbitrary file write issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, which allows remote code execution. RCE and file access is granted to everything hosted by ShareFile, be it on-premise or inside Citrix Cloud itself (both are internet facing). NOTE: unlike most CVEs, exploitability depends on the product version that was in use when a particular setup step was performed, NOT the product version that is in use during a current assessment of a CVE consumer's product inventory. Specifically, the vulnerability can be exploited if a storage zone was created by one of these product versions: 5.9.0, 5.8.0, 5.7.0, 5.6.0, 5.5.0, or earlier. This CVE differs from CVE-2020-7473 and CVE-2020-8982.

CVE-2020-8982 citrix vulnerability CVSS: 5.0 07 May 2020, 14:15 UTC

An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020. RCE and file access is granted to everything hosted by ShareFile, be it on-premise or inside Citrix Cloud itself (both are internet facing). NOTE: unlike most CVEs, exploitability depends on the product version that was in use when a particular setup step was performed, NOT the product version that is in use during a current assessment of a CVE consumer's product inventory. Specifically, the vulnerability can be exploited if a storage zone was created by one of these product versions: 5.9.0, 5.8.0, 5.7.0, 5.6.0, 5.5.0, or earlier. This CVE differs from CVE-2020-7473 and CVE-2020-8983.

CVE-2020-7473 citrix vulnerability CVSS: 5.0 07 May 2020, 14:15 UTC

In certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, allow unauthenticated attackers to access the documents and folders of ShareFile users. NOTE: unlike most CVEs, exploitability depends on the product version that was in use when a particular setup step was performed, NOT the product version that is in use during a current assessment of a CVE consumer's product inventory. Specifically, the vulnerability can be exploited if a storage zone was created by one of these product versions: 5.9.0, 5.8.0, 5.7.0, 5.6.0, 5.5.0, or earlier. This CVE differs from CVE-2020-8982 and CVE-2020-8983 but has essentially the same risk.

CVE-2020-6175 citrix vulnerability CVSS: 4.3 16 Mar 2020, 21:15 UTC

Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation.

CVE-2019-11345 citrix vulnerability CVSS: 4.3 10 Mar 2020, 14:15 UTC

Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow XSS.

CVE-2020-10112 citrix vulnerability CVSS: 5.8 06 Mar 2020, 21:15 UTC

Citrix Gateway 11.1, 12.0, and 12.1 allows Cache Poisoning. NOTE: Citrix disputes this as not a vulnerability. By default, Citrix ADC only caches static content served under certain URL paths for Citrix Gateway usage. No dynamic content is served under these paths, which implies that those cached pages would not change based on parameter values. All other data traffic going through Citrix Gateway are NOT cached by default

CVE-2020-10111 citrix vulnerability CVSS: 5.0 06 Mar 2020, 21:15 UTC

Citrix Gateway 11.1, 12.0, and 12.1 has an Inconsistent Interpretation of HTTP Requests. NOTE: Citrix disputes the reported behavior as not a security issue. Citrix ADC only caches HTTP/1.1 traffic for performance optimization

CVE-2020-10110 citrix vulnerability CVSS: 5.0 06 Mar 2020, 21:15 UTC

Citrix Gateway 11.1, 12.0, and 12.1 allows Information Exposure Through Caching. NOTE: Citrix disputes this as not a vulnerability. There is no sensitive information disclosure through the cache headers on Citrix ADC. The "Via" header lists cache protocols and recipients between the start and end points for a request or a response. The "Age" header provides the age of the cached response in seconds. Both headers are commonly used for proxy cache and the information is not sensitive

CVE-2012-4606 citrix vulnerability CVSS: 4.6 23 Jan 2020, 22:15 UTC

Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Update 3 contains a Local Privilege Escalation Vulnerability which could allow local users with access to a guest operating system to gain elevated privileges.

CVE-2012-4603 citrix vulnerability CVSS: 9.3 10 Jan 2020, 21:15 UTC

Citrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow remote attackers to execute arbitrary code by convincing a target to open a specially crafted file from an SMB or WebDAV fileserver.

CVE-2013-3620 citrix vulnerability CVSS: 5.0 02 Jan 2020, 18:15 UTC

Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards before SMT X8 312.

CVE-2013-3619 citrix vulnerability CVSS: 4.3 02 Jan 2020, 18:15 UTC

Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.

CVE-2019-19781 citrix vulnerability CVSS: 7.5 27 Dec 2019, 14:15 UTC

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

CVE-2019-18225 citrix vulnerability CVSS: 7.5 21 Oct 2019, 18:15 UTC

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway before 10.5 build 70.8, 11.x before 11.1 build 63.9, 12.0 before build 62.10, 12.1 before build 54.16, and 13.0 before build 41.28. An attacker with management-interface access can bypass authentication to obtain appliance administrative access. These products formerly used the NetScaler brand name.

CVE-2019-17366 citrix vulnerability CVSS: 6.5 09 Oct 2019, 22:15 UTC

Citrix Application Delivery Management (ADM) 12.1 before build 54.13 has Incorrect Access Control.

CVE-2019-13608 citrix vulnerability CVSS: 5.0 29 Aug 2019, 19:15 UTC

Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.

CVE-2019-12992 citrix vulnerability CVSS: 9.0 16 Jul 2019, 18:15 UTC

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6).

CVE-2019-12991 citrix vulnerability CVSS: 9.0 16 Jul 2019, 18:15 UTC

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).

CVE-2019-12990 citrix vulnerability CVSS: 10.0 16 Jul 2019, 18:15 UTC

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal.

CVE-2019-12989 citrix vulnerability CVSS: 7.5 16 Jul 2019, 18:15 UTC

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.

CVE-2019-12988 citrix vulnerability CVSS: 10.0 16 Jul 2019, 18:15 UTC

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6).

CVE-2019-12987 citrix vulnerability CVSS: 10.0 16 Jul 2019, 18:15 UTC

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6).

CVE-2019-12986 citrix vulnerability CVSS: 10.0 16 Jul 2019, 18:15 UTC

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6).

CVE-2019-12985 citrix vulnerability CVSS: 10.0 16 Jul 2019, 18:15 UTC

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6).

CVE-2014-3798 citrix vulnerability CVSS: 6.1 11 Jul 2019, 20:15 UTC

The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted Ethernet frame.

CVE-2019-12292 citrix vulnerability CVSS: 7.5 24 Jun 2019, 16:15 UTC

Citrix AppDNA before 7 1906.1.0.472 has Incorrect Access Control.

CVE-2019-9548 citrix vulnerability CVSS: 7.5 05 Jun 2019, 17:29 UTC

Citrix Application Delivery Management (ADM) 12.1.x before 12.1.50.33 has Incorrect Access Control.

CVE-2018-18571 citrix vulnerability CVSS: 6.4 05 Jun 2019, 15:29 UTC

An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any Mobile Application Management (MAM) enrolled device.

CVE-2019-10883 citrix vulnerability CVSS: 10.0 03 Jun 2019, 21:29 UTC

Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection.

CVE-2019-11634 citrix vulnerability CVSS: 7.5 22 May 2019, 17:29 UTC

Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

CVE-2019-12044 citrix vulnerability CVSS: 5.0 22 May 2019, 16:29 UTC

A Buffer Overflow exists in Citrix NetScaler Gateway 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23 and Citrix Application Delivery Controller 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23.

CVE-2019-7218 citrix vulnerability CVSS: 4.3 13 May 2019, 19:29 UTC

Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline victim's otp physical token or virtual app (like google authenticator) is able to bypass the first authentication phase (username/password mechanism) and log-in using username/otp combination only (phase 2 of 2FA).

CVE-2019-7217 citrix vulnerability CVSS: 5.0 13 May 2019, 19:29 UTC

Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on different server responses using the request to check the otp code. No authentication is required.

CVE-2019-11550 citrix vulnerability CVSS: 4.3 08 May 2019, 17:29 UTC

Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation.

CVE-2019-6485 citrix vulnerability CVSS: 4.3 22 Feb 2019, 23:29 UTC

Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 allow remote attackers to obtain sensitive plaintext information because of a TLS Padding Oracle Vulnerability when CBC-based cipher suites are enabled.

CVE-2018-19965 citrix vulnerability CVSS: 4.7 08 Dec 2018, 04:29 UTC

An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorrect CVE-2017-5754 (aka Meltdown) mitigation.

CVE-2018-19962 citrix vulnerability CVSS: 6.9 08 Dec 2018, 04:29 UTC

An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.

CVE-2018-19961 citrix vulnerability CVSS: 6.9 08 Dec 2018, 04:29 UTC

An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes.

CVE-2018-18517 citrix vulnerability CVSS: 3.5 24 Oct 2018, 21:29 UTC

Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x before 12.1.49.1 has XSS.

CVE-2018-18014 citrix vulnerability CVSS: 7.2 24 Oct 2018, 21:29 UTC

* Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by making requests to private services listening on ports 8000, 30000 and 30001. NOTE: the vendor disputes that this is a vulnerability, stating it is "already mitigated by the internal firewall that limits access to configuration services to localhost.

CVE-2018-18013 citrix vulnerability CVSS: 7.2 24 Oct 2018, 21:29 UTC

* Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If this service is supplied with raw serialised Java objects, it deserialises them back into Java objects in memory, giving rise to a remote code execution vulnerability. NOTE: the vendor disputes that this is a vulnerability, stating it is "already mitigated by the internal firewall that limits access to configuration services to localhost.

CVE-2018-17448 citrix vulnerability CVSS: 7.5 23 Oct 2018, 21:30 UTC

An Incorrect Access Control issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

CVE-2018-17447 citrix vulnerability CVSS: 5.0 23 Oct 2018, 21:30 UTC

An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

CVE-2018-17446 citrix vulnerability CVSS: 7.5 23 Oct 2018, 21:30 UTC

A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

CVE-2018-17445 citrix vulnerability CVSS: 7.5 23 Oct 2018, 21:30 UTC

A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

CVE-2018-17444 citrix vulnerability CVSS: 5.0 23 Oct 2018, 21:30 UTC

A Directory Traversal issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

CVE-2018-16969 citrix vulnerability CVSS: 4.0 26 Sep 2018, 21:29 UTC

Citrix ShareFile StorageZones Controller before 5.4.2 has Information Exposure Through an Error Message.

CVE-2018-16968 citrix vulnerability CVSS: 3.5 26 Sep 2018, 21:29 UTC

Citrix ShareFile StorageZones Controller before 5.4.2 allows Directory Traversal.

CVE-2018-14007 citrix vulnerability CVSS: 10.0 15 Aug 2018, 18:29 UTC

Citrix XenServer 7.1 and newer allows Directory Traversal.

CVE-2016-9603 citrix vulnerability CVSS: 9.0 27 Jul 2018, 21:29 UTC

A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU process or, potentially, execute arbitrary code on the host with privileges of the QEMU process.

CVE-2017-2620 citrix vulnerability CVSS: 9.0 27 Jul 2018, 19:29 UTC

Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process.

CVE-2017-2615 citrix vulnerability CVSS: 9.0 03 Jul 2018, 01:29 UTC

Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privileges of QEMU process on the host.

CVE-2018-3665 citrix vulnerability CVSS: 4.7 21 Jun 2018, 20:29 UTC

System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.

CVE-2018-10654 citrix vulnerability CVSS: 6.8 23 May 2018, 17:29 UTC

There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

CVE-2018-10653 citrix vulnerability CVSS: 7.5 23 May 2018, 17:29 UTC

There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

CVE-2018-10652 citrix vulnerability CVSS: 5.0 23 May 2018, 17:29 UTC

There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3.

CVE-2018-10651 citrix vulnerability CVSS: 5.8 23 May 2018, 17:29 UTC

There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

CVE-2018-10650 citrix vulnerability CVSS: 6.8 23 May 2018, 17:29 UTC

There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

CVE-2018-10649 citrix vulnerability CVSS: 4.3 23 May 2018, 17:29 UTC

There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3.

CVE-2018-10648 citrix vulnerability CVSS: 7.5 23 May 2018, 17:29 UTC

There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

CVE-2018-7218 citrix vulnerability CVSS: 10.0 17 May 2018, 19:29 UTC

The AppFirewall functionality in Citrix NetScaler Application Delivery Controller and NetScaler Gateway 10.5 before Build 68.7, 11.0 before Build 71.24, 11.1 before Build 58.13, and 12.0 before Build 57.24 allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2018-8897 citrix vulnerability CVSS: 7.2 08 May 2018, 18:29 UTC

A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example) privilege escalation in Windows, macOS, some Xen configurations, or FreeBSD, or a Linux kernel crash. The MOV to SS and POP SS instructions inhibit interrupts (including NMIs), data breakpoints, and single step trap exceptions until the instruction boundary following the next instruction (SDM Vol. 3A; section 6.8.3). (The inhibited data breakpoints are those on memory accessed by the MOV to SS or POP to SS instruction itself.) Note that debug exceptions are not inhibited by the interrupt enable (EFLAGS.IF) system flag (SDM Vol. 3A; section 2.3). If the instruction following the MOV to SS or POP to SS instruction is an instruction like SYSCALL, SYSENTER, INT 3, etc. that transfers control to the operating system at CPL < 3, the debug exception is delivered after the transfer to CPL < 3 is complete. OS kernels may not expect this order of events and may therefore experience unexpected behavior when it occurs.

CVE-2018-6811 citrix vulnerability CVSS: 4.3 06 Mar 2018, 20:29 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Citrix NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to inject arbitrary web script or HTML via the Citrix NetScaler interface.

CVE-2018-6810 citrix vulnerability CVSS: 5.0 06 Mar 2018, 20:29 UTC

Directory traversal vulnerability in NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allows remote attackers to traverse the directory on the target system via a crafted request.

CVE-2018-6809 citrix vulnerability CVSS: 10.0 06 Mar 2018, 20:29 UTC

NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to gain privilege on a target system.

CVE-2018-6808 citrix vulnerability CVSS: 5.0 06 Mar 2018, 20:29 UTC

NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to download arbitrary files on the target system.

CVE-2018-5314 citrix vulnerability CVSS: 5.0 01 Mar 2018, 17:29 UTC

Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition 9.3.0 allows remote attackers to execute a system command or read arbitrary files via an SSH login prompt.

CVE-2018-6186 citrix vulnerability CVSS: 9.0 01 Feb 2018, 14:29 UTC

Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/read_url URI by an authenticated attacker who has a webapp account. The attacker can gain access to the nsroot account, and execute remote commands with root privileges.

CVE-2017-17549 citrix vulnerability CVSS: 4.3 13 Dec 2017, 16:29 UTC

Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 allow remote attackers to obtain sensitive information from the backend client TLS handshake by leveraging use of TLS with Client Certificates and a Diffie-Hellman Ephemeral (DHE) key exchange.

CVE-2017-17382 citrix vulnerability CVSS: 4.3 13 Dec 2017, 16:29 UTC

Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 might allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.

CVE-2017-14602 citrix vulnerability CVSS: 9.0 26 Sep 2017, 14:29 UTC

A vulnerability has been identified in the management interface of Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before build 135.18, 10.5 before build 66.9, 10.5e before build 60.7010.e, 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13 (except for build 41.24) that, if exploited, could allow an attacker with access to the NetScaler management interface to gain administrative access to the appliance.

CVE-2017-12137 citrix vulnerability CVSS: 7.2 24 Aug 2017, 14:29 UTC

arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.

CVE-2017-12136 citrix vulnerability CVSS: 6.9 24 Aug 2017, 14:29 UTC

Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling.

CVE-2017-12135 citrix vulnerability CVSS: 4.6 24 Aug 2017, 14:29 UTC

Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants.

CVE-2017-12134 citrix vulnerability CVSS: 7.2 24 Aug 2017, 14:29 UTC

The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and consequently obtain sensitive memory information, cause a denial of service, or gain host OS privileges by leveraging incorrect block IO merge-ability calculation.

CVE-2015-7705 citrix vulnerability CVSS: 7.5 07 Aug 2017, 20:29 UTC

The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.

CVE-2015-7704 citrix vulnerability CVSS: 5.0 07 Aug 2017, 20:29 UTC

The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.

CVE-2015-3642 citrix vulnerability CVSS: 4.3 02 Aug 2017, 19:29 UTC

The TLS and DTLS processing functionality in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices with firmware 9.x before 9.3 Build 68.5, 10.0 through Build 78.6, 10.1 before Build 130.13, 10.1.e before Build 130.1302.e, 10.5 before Build 55.8, and 10.5.e before Build 55.8007.e makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).

CVE-2017-6316 citrix vulnerability CVSS: 10.0 20 Jul 2017, 04:29 UTC

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID.

CVE-2017-9231 citrix vulnerability CVSS: 5.0 16 Jun 2017, 22:29 UTC

XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via unspecified vectors.

CVE-2016-6877 citrix vulnerability CVSS: 2.6 05 May 2017, 20:29 UTC

Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving the HTTP Host header and a cached page. NOTE: the vendor reports "our internal analysis of this issue concluded that this was not a valid vulnerability" because an exploitation scenario would involve a man-in-the-middle attack against a TLS session

CVE-2017-7219 citrix vulnerability CVSS: 9.0 13 Apr 2017, 14:59 UTC

A heap overflow vulnerability in Citrix NetScaler Gateway versions 10.1 before 135.8/135.12, 10.5 before 65.11, 11.0 before 70.12, and 11.1 before 52.13 allows a remote authenticated attacker to run arbitrary commands via unspecified vectors.

CVE-2016-9637 citrix vulnerability CVSS: 3.7 17 Feb 2017, 02:59 UTC

The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS administrators to gain qemu process privileges via vectors involving an out-of-range ioport access.

CVE-2017-5573 citrix vulnerability CVSS: 4.0 30 Jan 2017, 16:59 UTC

An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated read-only administrator can cancel tasks of other administrators.

CVE-2017-5572 citrix vulnerability CVSS: 5.5 30 Jan 2017, 16:59 UTC

An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated read-only administrator can corrupt the host database.

CVE-2016-10025 citrix vulnerability CVSS: 2.1 26 Jan 2017, 15:59 UTC

VMFUNC emulation in Xen 4.6.x through 4.8.x on x86 systems using AMD virtualization extensions (aka SVM) allows local HVM guest OS users to cause a denial of service (hypervisor crash) by leveraging a missing NULL pointer check.

CVE-2016-10024 citrix vulnerability CVSS: 4.9 26 Jan 2017, 15:59 UTC

Xen through 4.8.x allows local x86 PV guest OS kernel administrators to cause a denial of service (host hang or crash) by modifying the instruction stream asynchronously while performing certain kernel operations.

CVE-2016-9386 citrix vulnerability CVSS: 4.6 23 Jan 2017, 21:59 UTC

The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory, which might allow local HVM guest users to gain privileges via vectors involving "unexpected" base/limit values.

CVE-2016-9385 citrix vulnerability CVSS: 4.9 23 Jan 2017, 21:59 UTC

The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of service (host crash) by leveraging lack of canonical address checks.

CVE-2016-9383 citrix vulnerability CVSS: 7.2 23 Jan 2017, 21:59 UTC

Xen, when running on a 64-bit hypervisor, allows local x86 guest OS users to modify arbitrary memory and consequently obtain sensitive information, cause a denial of service (host crash), or execute arbitrary code on the host by leveraging broken emulation of bit test instructions.

CVE-2016-9382 citrix vulnerability CVSS: 4.6 23 Jan 2017, 21:59 UTC

Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to gain privileges or cause a denial of service (guest OS crash) by leveraging a guest operating system that uses hardware task switching and allows a new task to start in VM86 mode.

CVE-2016-9381 citrix vulnerability CVSS: 6.9 23 Jan 2017, 21:59 UTC

Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double fetch" vulnerability.

CVE-2016-9380 citrix vulnerability CVSS: 4.6 23 Jan 2017, 21:59 UTC

The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via NUL bytes in the bootloader configuration file.

CVE-2016-9379 citrix vulnerability CVSS: 4.6 23 Jan 2017, 21:59 UTC

The pygrub boot loader emulator in Xen, when S-expression output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via string quotes and S-expressions in the bootloader configuration file.

CVE-2016-9680 citrix vulnerability CVSS: 5.0 18 Jan 2017, 22:59 UTC

Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive information from kernel memory via unspecified vectors.

CVE-2016-9679 citrix vulnerability CVSS: 7.5 18 Jan 2017, 22:59 UTC

Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code by overwriting a function pointer.

CVE-2016-9678 citrix vulnerability CVSS: 7.5 18 Jan 2017, 22:59 UTC

Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.

CVE-2016-9677 citrix vulnerability CVSS: 5.0 18 Jan 2017, 22:59 UTC

Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified vectors.

CVE-2016-9676 citrix vulnerability CVSS: 7.5 18 Jan 2017, 22:59 UTC

Buffer overflow in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.

CVE-2016-9111 citrix vulnerability CVSS: 4.6 07 Nov 2016, 11:59 UTC

Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication requirement by leveraging physical access to a VDI for temporary disconnection of a LAN cable. NOTE: as of 20161208, the vendor could not reproduce the issue, stating "the researcher was unable to provide us with information that would allow us to confirm the behaviour and, despite extensive investigation on test deployments of supported products, we were unable to reproduce the behaviour as he described. The researcher has also, despite additional requests for information, ceased to respond to us."

CVE-2016-9028 citrix vulnerability CVSS: 5.8 28 Oct 2016, 15:59 UTC

Unauthorized redirect vulnerability in Citrix NetScaler ADC before 10.1 135.8, 10.5 61.11, 11.0 65.31/65.35F and 11.1 47.14 allows a remote attacker to steal session cookies of a legitimate AAA user via manipulation of Host header.

CVE-2016-6273 citrix vulnerability CVSS: 5.0 07 Oct 2016, 14:59 UTC

The lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) before 2015 SP5 and 2016 before R1 SP1, as used by Citrix License Server for Windows before 11.14.0.1 and Citrix License Server VPX before 11.14.0.1, allows remote attackers to cause a denial of service (crash) via a type 2F packet with a '01 19' opcode.

CVE-2016-6276 citrix vulnerability CVSS: 7.2 26 Sep 2016, 14:59 UTC

Citrix Linux Virtual Delivery Agent (aka VDA, formerly Linux Virtual Desktop) before 1.4.0 allows local users to gain root privileges via unspecified vectors.

CVE-2016-6493 citrix vulnerability CVSS: 7.5 19 Aug 2016, 21:59 UTC

Citrix XenApp 6.x before 6.5 HRP07 and 7.x before 7.9 and Citrix XenDesktop before 7.9 might allow attackers to weaken an unspecified security mitigation via vectors related to memory permission.

CVE-2016-6259 citrix vulnerability CVSS: 4.9 02 Aug 2016, 16:59 UTC

Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check.

CVE-2016-6258 citrix vulnerability CVSS: 7.2 02 Aug 2016, 16:59 UTC

The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.

CVE-2016-5109 citrix vulnerability CVSS: 2.1 13 Jul 2016, 15:59 UTC

Citrix Worx Home for iOS before 10.3.6 and XenMobile MDX Toolkit for iOS before 10.3.6 might allow physically proximate attackers to bypass in-application Apple Touch ID authentication via unspecified vectors, related to an application requiring re-authentication.

CVE-2016-5433 citrix vulnerability CVSS: 5.8 17 Jun 2016, 15:59 UTC

Citrix iOS Receiver before 7.0 allows attackers to cause TLS certificates to be incorrectly validated via unspecified vectors.

CVE-2016-5302 citrix vulnerability CVSS: 7.5 13 Jun 2016, 14:59 UTC

Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a host by leveraging credentials for an Active Directory account.

CVE-2016-4945 citrix vulnerability CVSS: 4.3 01 Jun 2016, 22:59 UTC

Cross-site scripting (XSS) vulnerability in vpn/js/gateway_login_form_view.js in Citrix NetScaler Gateway 11.0 before Build 66.11 allows remote attackers to inject arbitrary web script or HTML via the NSC_TMAC cookie.

CVE-2016-4810 citrix vulnerability CVSS: 5.0 01 Jun 2016, 22:59 UTC

Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenDesktop Delivery Controller via unspecified vectors.

CVE-2016-3712 citrix vulnerability CVSS: 2.1 11 May 2016, 21:59 UTC

Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.

CVE-2016-3710 citrix vulnerability CVSS: 7.2 11 May 2016, 21:59 UTC

The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.

CVE-2015-7999 citrix vulnerability CVSS: 6.5 14 Apr 2016, 14:59 UTC

Multiple SQL injection vulnerabilities in the Administration Web UI servlets in Citrix Command Center before 5.1 Build 36.7 and 5.2 before Build 44.11 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVE-2015-8555 citrix vulnerability CVSS: 5.0 13 Apr 2016, 15:59 UTC

Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains to obtain sensitive information from other domains via unspecified vectors.

CVE-2016-2789 citrix vulnerability CVSS: 4.3 07 Apr 2016, 23:59 UTC

Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling Patch 4, and 10.3 before Rolling Patch 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2016-2072 citrix vulnerability CVSS: 4.3 17 Feb 2016, 15:59 UTC

The Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, 10.5.e before Build 59.1305.e, and 10.1 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

CVE-2016-2071 citrix vulnerability CVSS: 10.0 17 Feb 2016, 15:59 UTC

Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, and 10.5.e before Build 59.1305.e allows remote attackers to gain privileges via unspecified NS Web GUI commands.

CVE-2016-1571 citrix vulnerability CVSS: 4.7 22 Jan 2016, 15:59 UTC

The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address in an INVVPID instruction, which triggers a hypervisor bug check.

CVE-2015-7998 citrix vulnerability CVSS: 5.0 17 Nov 2015, 15:59 UTC

The administration UI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allows attackers to obtain sensitive information via unspecified vectors.

CVE-2015-7997 citrix vulnerability CVSS: 4.3 17 Nov 2015, 15:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in the Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2015-7996 citrix vulnerability CVSS: 5.0 17 Nov 2015, 15:59 UTC

The Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allow attackers to obtain credentials via the browser cache.

CVE-2015-6672 citrix vulnerability CVSS: 4.3 17 Sep 2015, 16:59 UTC

Cross-site scripting (XSS) vulnerability in the Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 before Build 57.7, and 10.5e before Build 56.1505.e allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2015-5538 citrix vulnerability CVSS: 10.0 17 Sep 2015, 16:59 UTC

Multiple unspecified vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 before Build 57.7, and 10.5e before Build 56.1505.e allow remote attackers to gain privileges via unknown vectors, related to the (1) Command Line Interface (CLI) and the (2) Web User Interface (UI).

CVE-2015-5080 citrix vulnerability CVSS: 9.0 16 Jul 2015, 14:59 UTC

The Management Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before 10.1.132.8, 10.5 before Build 56.15, and 10.5.e before Build 56.1505.e allows remote authenticated users to execute arbitrary shell commands via shell metacharacters in the filter parameter to rapi/ipsec_logs.

CVE-2015-4106 citrix vulnerability CVSS: 4.6 03 Jun 2015, 20:59 UTC

QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact via unknown vectors.

CVE-2015-2829 citrix vulnerability CVSS: 7.8 12 May 2015, 19:59 UTC

Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.5 Build 53.9 through 55.8 and 10.5.e Build 53-9010.e allow remote attackers to cause a denial of service (reboot) via unspecified vectors.

CVE-2015-2841 citrix vulnerability CVSS: 5.0 03 Apr 2015, 14:59 UTC

Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restrictions via a crafted Content-Type header, as demonstrated by the application/octet-stream and text/xml Content-Types.

CVE-2015-2840 citrix vulnerability CVSS: 4.3 03 Apr 2015, 14:59 UTC

Cross-site scripting (XSS) vulnerability in help/rt/large_search.html in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to inject arbitrary web script or HTML via the searchQuery parameter.

CVE-2015-2839 citrix vulnerability CVSS: 4.3 03 Apr 2015, 14:59 UTC

The Nitro API in Citrix NetScaler before 10.5 build 52.3nc uses an incorrect Content-Type when returning an error message, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the file_name JSON member in params/xen_hotfix/0 to nitro/v1/config/xen_hotfix.

CVE-2015-2838 citrix vulnerability CVSS: 6.8 03 Apr 2015, 14:59 UTC

Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary commands as nsroot via shell metacharacters in the file_name JSON member in params/xen_hotfix/0 to nitro/v1/config/xen_hotfix.

CVE-2015-2683 citrix vulnerability CVSS: 7.5 26 Mar 2015, 14:59 UTC

Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 does not properly restrict access to the Advent Java Management Extensions (JMX) Servlet, which allows remote attackers to execute arbitrary code via unspecified vectors to servlets/Jmx_dynamic.

CVE-2015-2682 citrix vulnerability CVSS: 5.0 26 Mar 2015, 14:59 UTC

Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via a direct request to conf/securitydbData.xml.

CVE-2014-8580 citrix vulnerability CVSS: 4.9 07 Nov 2014, 19:55 UTC

Citrix NetScaler Application Delivery Controller and NetScaler Gateway 10.5.50.10 before 10.5-52.11, 10.1.122.17 before 10.1-129.11, and 10.1-120.1316.e before 10.1-129.1105.e, when using unspecified configurations, allows remote authenticated users to access "network resources" of other users via unknown vectors.

CVE-2014-8495 citrix vulnerability CVSS: 5.0 31 Oct 2014, 14:55 UTC

Citrix XenMobile MDX Toolkit before 9.0.4, when used to wrap iOS 8 applications, does not properly encrypt cached application data, which allows context-dependent attackers to obtain sensitive information by reading the cache.

CVE-2014-7140 citrix vulnerability CVSS: 7.5 21 Oct 2014, 14:55 UTC

Unspecified vulnerability in the management interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.x before 10.1-129.11 and 10.5 before 10.5-50.10 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2014-7169 citrix vulnerability CVSS: 10.0 25 Sep 2014, 01:55 UTC

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.

CVE-2014-6271 citrix vulnerability CVSS: 10.0 24 Sep 2014, 18:48 UTC

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

CVE-2011-2593 citrix vulnerability CVSS: 6.8 12 Aug 2014, 20:55 UTC

Integer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9.x before 9.3-57.5 and 10.0 before 10.0-69.4 allows remote attackers to execute arbitrary code via a crafted Content-Length HTTP header, which triggers a heap-based buffer overflow.

CVE-2014-4948 citrix vulnerability CVSS: 6.4 22 Jul 2014, 20:55 UTC

Unspecified vulnerability in Citrix XenServer 6.2 Service Pack 1 and earlier allows attackers to cause a denial of service and obtain sensitive information by modifying the guest virtual hard disk (VHD).

CVE-2014-4947 citrix vulnerability CVSS: 10.0 22 Jul 2014, 20:55 UTC

Buffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earlier has unspecified impact and attack vectors.

CVE-2014-4347 citrix vulnerability CVSS: 5.0 16 Jul 2014, 14:19 UTC

Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) before 9.3-62.4 and 10.x before 10.1-126.12 allows attackers to obtain sensitive information via vectors related to a cookie.

CVE-2014-4346 citrix vulnerability CVSS: 4.3 16 Jul 2014, 14:19 UTC

Cross-site scripting (XSS) vulnerability in administration user interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) 10.1 before 10.1-126.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2014-4700 citrix vulnerability CVSS: 4.9 11 Jul 2014, 14:55 UTC

Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user's desktop via unspecified vectors.

CVE-2011-2592 citrix vulnerability CVSS: 9.3 18 Jun 2014, 14:55 UTC

Heap-based buffer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9.x before 9.3-57.5 and 10.0 before 10.0-69.4 allows remote attackers to execute arbitrary code via a long CSEC HTTP response header.

CVE-2014-3780 citrix vulnerability CVSS: 7.5 30 May 2014, 14:55 UTC

Unspecified vulnerability in Citrix VDI-In-A-Box 5.3.x before 5.3.8 and 5.4.x before 5.4.4 allows remote attackers to bypass authentication via unspecified vectors, related to a Java servlet.

CVE-2013-2758 citrix vulnerability CVSS: 5.0 23 May 2014, 14:55 UTC

Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C uses a hash of a predictable sequence, which makes it easier for remote attackers to guess the console access URL via a brute force attack.

CVE-2013-2757 citrix vulnerability CVSS: 7.5 23 May 2014, 14:55 UTC

Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C does not properly restrict access to VNC ports on the management network, which allows remote attackers to have unspecified impact via unknown vectors.

CVE-2013-2756 citrix vulnerability CVSS: 5.0 23 May 2014, 14:55 UTC

Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypass the console proxy authentication by leveraging knowledge of the source code.

CVE-2014-1899 citrix vulnerability CVSS: 4.3 02 May 2014, 14:55 UTC

Cross-site scripting (XSS) vulnerability in Citrix NetScaler Gateway (formerly Citrix Access Gateway Enterprise Edition) 9.x before 9.3.66.5 and 10.x before 10.1.123.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2014-2882 citrix vulnerability CVSS: 10.0 01 May 2014, 17:28 UTC

Unspecified vulnerability in the management GUI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unspecified impact and vectors, related to certificate validation.

CVE-2014-2881 citrix vulnerability CVSS: 10.0 01 May 2014, 17:28 UTC

Unspecified vulnerability in the Diffie-Hellman key agreement implementation in the management GUI Java applet in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unknown impact and vectors.

CVE-2014-2690 citrix vulnerability CVSS: 2.1 15 Apr 2014, 14:55 UTC

Citrix VDI-in-a-Box 5.3.x before 5.3.6 and 5.4.x before 5.4.3 allows local users to obtain administrator credentials by reading the log.

CVE-2013-6943 citrix vulnerability CVSS: 5.0 11 Mar 2014, 13:00 UTC

Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to conduct an LDAP injection attack via vectors related to SSH and Web management usernames.

CVE-2013-6944 citrix vulnerability CVSS: 4.3 11 Mar 2014, 13:00 UTC

Cross-site scripting (XSS) vulnerability in the user interface in the AAA TM vServer in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2013-6941 citrix vulnerability CVSS: 10.0 11 Mar 2014, 13:00 UTC

Unspecified vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows users to "breakout" of the shell via unknown vectors.

CVE-2013-6942 citrix vulnerability CVSS: 6.8 11 Mar 2014, 13:00 UTC

Cross-site request forgery (CSRF) vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2013-6939 citrix vulnerability CVSS: 5.0 11 Mar 2014, 13:00 UTC

Unspecified vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows attackers to cause a denial of service via unknown vectors, related to "RADIUS authentication."

CVE-2013-6940 citrix vulnerability CVSS: 5.0 11 Mar 2014, 13:00 UTC

Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 logs user credentials, which allows attackers to obtain sensitive information via unspecified vectors.

CVE-2013-6938 citrix vulnerability CVSS: 5.0 11 Mar 2014, 13:00 UTC

Unspecified vulnerability in the Service VM in Citrix NetScaler SDX 9.3 before 9.3-64.4 and 10.0 before 10.0-77.5 and Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows attackers to cause a denial of service via unknown vectors, related to the "Virtual Machine Daemon."

CVE-2014-1910 citrix vulnerability CVSS: 5.8 21 Feb 2014, 15:30 UTC

Citrix ShareFile Mobile and ShareFile Mobile for Tablets before 2.4.4 for Android do not verify X.509 certificates from SSL servers, which allow man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-1663 citrix vulnerability CVSS: 5.0 06 Feb 2014, 17:00 UTC

Unspecified vulnerability in Citrix XenMobile Device Manager server (formerly Zenprise Device Manager server) 8.5, 8.6, and MDM 8.0.1 allows remote attackers to obtain sensitive information via unknown vectors.

CVE-2014-1664 citrix vulnerability CVSS: 5.0 26 Jan 2014, 20:55 UTC

The Citrix GoToMeeting application 5.0.799.1238 for Android logs HTTP requests containing sensitive information, which allows attackers to obtain user IDs, meeting details, and authentication tokens via an application that reads the system log file.

CVE-2013-6077 citrix vulnerability CVSS: 5.8 05 Nov 2013, 18:55 UTC

Citrix XenDesktop 7.0, when upgraded from XenDesktop 5.x, does not properly enforce policy rule permissions, which allows remote attackers to bypass intended restrictions.

CVE-2013-6011 citrix vulnerability CVSS: 7.8 04 Oct 2013, 17:55 UTC

Citrix NetScaler Application Delivery Controller (ADC) 10.0 before 10.0-76.7 allows remote attackers to cause a denial of service (nsconfigd crash and appliance reboot) via a crafted request.

CVE-2013-2940 citrix vulnerability CVSS: 10.0 12 Sep 2013, 18:37 UTC

Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.

CVE-2013-2939 citrix vulnerability CVSS: 10.0 12 Sep 2013, 18:37 UTC

Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.

CVE-2013-2938 citrix vulnerability CVSS: 10.0 12 Sep 2013, 18:37 UTC

Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.

CVE-2013-2937 citrix vulnerability CVSS: 10.0 12 Sep 2013, 18:37 UTC

Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, related to debugging messages, a different vulnerability than other CVEs listed in CTX137162.

CVE-2013-2936 citrix vulnerability CVSS: 10.0 12 Sep 2013, 18:37 UTC

Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.

CVE-2013-2935 citrix vulnerability CVSS: 10.0 12 Sep 2013, 18:37 UTC

Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.

CVE-2013-2934 citrix vulnerability CVSS: 10.0 12 Sep 2013, 18:37 UTC

Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 does not properly restrict access to web services, which has unspecified impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.

CVE-2013-2933 citrix vulnerability CVSS: 10.0 12 Sep 2013, 18:37 UTC

Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.

CVE-2013-2601 citrix vulnerability CVSS: 7.5 12 Sep 2013, 18:37 UTC

The NDVM in Citrix XenClient XT before 2.1.3 and 3.x before 3.1.4 allows remote attackers to execute arbitrary commands by using the UIVM to create a network connection.

CVE-2013-2767 citrix vulnerability CVSS: 5.4 25 Apr 2013, 20:55 UTC

Unspecified vulnerability in Citrix NetScaler Access Gateway Enterprise Edition (AGEE) before 9.3.62.4 and 10.x through 10.0.74.4, and NetScaler AGEE Common Criteria build before 9.3.53.6, allows remote attackers to bypass intended intranet access restrictions via unknown vectors.

CVE-2013-2263 citrix vulnerability CVSS: 5.0 19 Mar 2013, 14:55 UTC

Unspecified vulnerability in Citrix Access Gateway Standard Edition 5.0.x before 5.0.4.223524 allows remote attackers to access network resources via unknown attack vectors.

CVE-2012-5616 citrix vulnerability CVSS: 1.5 22 Jan 2013, 23:55 UTC

Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local users to obtain (1) the SSH private key as recorded by the createSSHKeyPair API, (2) the password of an added host as recorded by the AddHost API, or the password of an added VM as recorded by the (3) DeployVM or (4) ResetPasswordForVM API.

CVE-2012-6314 citrix vulnerability CVSS: 5.0 26 Dec 2012, 22:55 UTC

Citrix XenDesktop Virtual Desktop Agent (VDA) 5.6.x before 5.6.200, when making changes to the server-side policy that control USB redirection, does not propagate changes to the VDA, which allows authenticated users to retain access to the USB device.

CVE-2012-5161 citrix vulnerability CVSS: 9.3 26 Dec 2012, 22:55 UTC

The XML Service interface in Citrix XenApp 6.5 and 6.5 Feature Pack 1 allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2012-5512 citrix vulnerability CVSS: 3.2 13 Dec 2012, 11:53 UTC

Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) or obtain sensitive information via unspecified vectors.

CVE-2012-3516 citrix vulnerability CVSS: 6.9 23 Nov 2012, 20:55 UTC

The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4.2 and Citrix XenServer 6.0.2 allows local guest kernels or administrators to cause a denial of service (host crash) and possibly gain privileges via a crafted grant reference that triggers a write to an arbitrary hypervisor memory location.

CVE-2012-3498 citrix vulnerability CVSS: 5.6 23 Nov 2012, 20:55 UTC

PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host crash) and possibly read hypervisor or guest memory via vectors related to a missing range check of map->index.

CVE-2012-3496 citrix vulnerability CVSS: 4.7 23 Nov 2012, 20:55 UTC

XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when translating paging mode is not used, allows local PV OS guest kernels to cause a denial of service (BUG triggered and host crash) via invalid flags such as MEMF_populate_on_demand.

CVE-2012-3495 citrix vulnerability CVSS: 6.1 23 Nov 2012, 20:55 UTC

The physdev_get_free_pirq hypercall in arch/x86/physdev.c in Xen 4.1.x and Citrix XenServer 6.0.2 and earlier uses the return value of the get_free_pirq function as an array index without checking that the return value indicates an error, which allows guest OS users to cause a denial of service (invalid memory write and host crash) and possibly gain privileges via unspecified vectors.

CVE-2012-3494 citrix vulnerability CVSS: 2.1 23 Nov 2012, 20:55 UTC

The set_debugreg hypercall in include/asm-x86/debugreg.h in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when running on x86-64 systems, allows local OS guest users to cause a denial of service (host crash) by writing to the reserved bits of the DR7 debug control register.

CVE-2012-4501 citrix vulnerability CVSS: 10.0 26 Oct 2012, 10:39 UTC

Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API calls to delete VMs.

CVE-2012-4068 citrix vulnerability CVSS: 7.5 26 Jul 2012, 19:55 UTC

Heap-based buffer overflow in the SoapServer service in Citrix Provisioning Services 5.0, 5.1, 5.6, 5.6 SP1, 6.0, and 6.1 allows remote attackers to execute arbitrary code via a crafted string associated with date and time data.

CVE-2012-0217 citrix vulnerability CVSS: 7.2 12 Jun 2012, 22:55 UTC

The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems, when running on an Intel processor, incorrectly uses the sysret path in cases where a certain address is not a canonical address, which allows local users to gain privileges via a crafted application. NOTE: because this issue is due to incorrect use of the Intel specification, it should have been split into separate identifiers; however, there was some value in preserving the original mapping of the multi-codebase coordinated-disclosure effort to a single identifier.

CVE-2011-3262 citrix vulnerability CVSS: 2.1 19 Aug 2011, 20:55 UTC

tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allows local users to cause a denial of service (management software infinite loop and management domain resource consumption) via unspecified vectors related to "Lack of error checking in the decompression loop."

CVE-2011-1898 citrix vulnerability CVSS: 7.4 12 Aug 2011, 18:55 UTC

Xen 4.1 before 4.1.1 and 4.0 before 4.0.2, when using PCI passthrough on Intel VT-d chipsets that do not have interrupt remapping, allows guest OS users to gain host OS privileges by "using DMA to generate MSI interrupts by writing to the interrupt injection registers."

CVE-2011-1583 citrix vulnerability CVSS: 6.9 12 Aug 2011, 18:55 UTC

Multiple integer overflows in tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allow local users to cause a denial of service and possibly execute arbitrary code via a crafted paravirtualised guest kernel image that triggers (1) a buffer overflow during a decompression loop or (2) an out-of-bounds read in the loader involving unspecified length fields.

CVE-2011-2883 citrix vulnerability CVSS: 9.3 21 Jul 2011, 23:55 UTC

The NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 attempts to validate signed DLLs by checking the certificate subject, not the signature, which allows man-in-the-middle attackers to execute arbitrary code via HTTP header data referencing a DLL that was signed with a crafted certificate.

CVE-2011-2882 citrix vulnerability CVSS: 9.3 21 Jul 2011, 23:55 UTC

Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 allows remote attackers to execute arbitrary code via crafted HTTP header data.

CVE-2011-1101 citrix vulnerability CVSS: 6.8 25 Feb 2011, 19:00 UTC

Multiple unspecified vulnerabilities in a third-party component of the Citrix Licensing Administration Console 11.6, formerly License Management Console, allow remote attackers to (1) access unauthorized "license administration functionality" or (2) cause a denial of service via unknown vectors.

CVE-2010-4255 citrix vulnerability CVSS: 6.1 25 Jan 2011, 01:00 UTC

The fixup_page_fault function in arch/x86/traps.c in Xen 4.0.1 and earlier on 64-bit platforms, when paravirtualization is enabled, does not verify that kernel mode is used to call the handle_gdt_ldt_mapping_fault function, which allows guest OS users to cause a denial of service (host OS BUG_ON) via a crafted memory access.

CVE-2010-4238 citrix vulnerability CVSS: 5.5 22 Jan 2011, 22:00 UTC

The vbd_create function in Xen 3.1.2, when the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 is used, allows guest OS users to cause a denial of service (host OS panic) via an attempted access to a virtual CD-ROM device through the blkback driver. NOTE: some of these details are obtained from third party information.

CVE-2010-4566 citrix vulnerability CVSS: 9.3 14 Jan 2011, 23:00 UTC

The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers to execute arbitrary commands via shell metacharacters in the password field.

CVE-2010-4247 citrix vulnerability CVSS: 5.5 11 Jan 2011, 03:00 UTC

The do_block_io_op function in (1) drivers/xen/blkback/blkback.c and (2) drivers/xen/blktap/blktap.c in Xen before 3.4.0 for the Linux kernel 2.6.18, and possibly other versions, allows guest OS users to cause a denial of service (infinite loop and CPU consumption) via a large production request index to the blkback or blktap back-end drivers. NOTE: some of these details are obtained from third party information.

CVE-2010-4515 citrix vulnerability CVSS: 4.3 09 Dec 2010, 21:00 UTC

Cross-site scripting (XSS) vulnerability in Citrix Web Interface 5.0, 5.1, and 5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-6477 and CVE-2009-2454.

CVE-2010-3699 citrix vulnerability CVSS: 2.7 08 Dec 2010, 20:00 UTC

The backend driver in Xen 3.x allows guest OS users to cause a denial of service via a kernel thread leak, which prevents the device and guest OS from being shut down or create a zombie domain, causes a hang in zenwatch, or prevents unspecified xm commands from working properly, related to (1) netback, (2) blkback, or (3) blktap.

CVE-2010-2991 citrix vulnerability CVSS: 9.3 11 Aug 2010, 20:00 UTC

The IICAClient interface in the ICAClient library in the ICA Client ActiveX Object (aka ICO) component in Citrix Online Plug-in for Windows for XenApp & XenDesktop before 12.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HTML document that triggers the reading of a .ICA file.

CVE-2010-2619 citrix vulnerability CVSS: 1.9 02 Jul 2010, 20:30 UTC

Citrix XenServer 5.0 Update 2 and earlier, and 5.5 Update 1 and earlier, when using a pvops kernel, allows guest users to cause a denial of service in the host via unspecified vectors that trigger "incorrectly set flags."

CVE-2010-0633 citrix vulnerability CVSS: 4.6 12 Feb 2010, 22:30 UTC

Unspecified vulnerability in Citrix XenServer 5.0 Update 3 and earlier, and 5.5, allows local users to bypass authentication and execute unspecified Xen API (XAPI) calls via unknown vectors.

CVE-2009-3936 citrix vulnerability CVSS: 5.8 13 Nov 2009, 16:30 UTC

Unspecified vulnerability in Citrix Online Plug-in for Windows 11.0.x before 11.0.150 and 11.x before 11.2, Online Plug-in for Mac before 11.0, Receiver for iPhone before 1.0.3, and ICA Java, Mac, UNIX, and Windows Clients for XenApp and XenDesktop allows remote attackers to impersonate the SSL/TLS server and bypass authentication via a crafted certificate, a different vulnerability than CVE-2009-3555.

CVE-2009-3760 citrix vulnerability CVSS: 7.5 22 Oct 2009, 17:30 UTC

Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to inject arbitrary PHP code into include/config.ini.php via the pool1 parameter. NOTE: some of these details are obtained from third party information.

CVE-2009-3759 citrix vulnerability CVSS: 6.0 22 Oct 2009, 17:30 UTC

Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to hijack the authentication of administrators for (1) requests that change the password via the username parameter to config/changepw.php or (2) stop a virtual machine via the stop_vmname parameter to hardstopvm.php. NOTE: some of these details are obtained from third party information.

CVE-2009-3758 citrix vulnerability CVSS: 7.5 22 Oct 2009, 17:30 UTC

SQL injection vulnerability in login.php in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.

CVE-2009-3757 citrix vulnerability CVSS: 4.3 22 Oct 2009, 17:30 UTC

Multiple cross-site scripting (XSS) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to config/edituser.php; (2) location, (3) sessionid, and (4) vmname parameters to console.php; (5) vmrefid and (6) vmname parameters to forcerestart.php; and (7) vmname and (8) vmrefid parameters to forcesd.php. NOTE: some of these details are obtained from third party information.

CVE-2009-2454 citrix vulnerability CVSS: 4.3 14 Jul 2009, 14:30 UTC

Cross-site scripting (XSS) vulnerability in Citrix Web Interface 4.6, 5.0, and 5.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2009-2453 citrix vulnerability CVSS: 7.5 14 Jul 2009, 14:30 UTC

Citrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Advanced Edition filters, which allows attackers to bypass intended access restrictions via unknown vectors.

CVE-2009-2452 citrix vulnerability CVSS: 10.0 14 Jul 2009, 14:30 UTC

Multiple unspecified vulnerabilities in Citrix Licensing 11.5 have unknown impact and attack vectors, related to "underlying components of the License Management Console."

CVE-2009-2214 citrix vulnerability CVSS: 5.0 25 Jun 2009, 23:14 UTC

The Secure Gateway service in Citrix Secure Gateway 3.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an unspecified request.

CVE-2009-2213 citrix vulnerability CVSS: 6.3 25 Jun 2009, 23:14 UTC

The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Authorization Action option, which might allow remote authenticated users to bypass intended access restrictions.

CVE-2008-6830 citrix vulnerability CVSS: 4.0 08 Jun 2009, 19:30 UTC

The disconnection feature in Citrix Web Interface 5.0 and 5.0.1 for Java Application Servers does not properly terminate a user's web interface session, which allows attackers with access to the same browser instance to gain access to the user's Web Interface session. NOTE: the attacker must also have valid credentials to the Web Interface.

CVE-2008-6561 citrix vulnerability CVSS: 1.9 31 Mar 2009, 17:30 UTC

Citrix Presentation Server Client for Windows before 10.200 does not clear "credential information" from process memory in unspecified circumstances, which might allow local users to gain privileges.

CVE-2008-5882 citrix vulnerability CVSS: 7.5 09 Jan 2009, 18:30 UTC

SQL injection vulnerability in login.asp in Citrix Application Gateway - Broadcast Server (BCS) before 6.1, as used by Avaya AG250 - Broadcast Server before 2.0 and possibly other products, allows remote attackers to execute arbitrary SQL commands via the txtUID parameter.

CVE-2008-5716 citrix vulnerability CVSS: 7.2 24 Dec 2008, 18:29 UTC

xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue exists because of erroneous set_permissions calls in the fix for CVE-2008-4405.

CVE-2008-5121 citrix vulnerability CVSS: 7.2 18 Nov 2008, 00:30 UTC

dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, and (3) SafeNet SoftRemote and HighAssurance Remote, allows local users to gain privileges via a crafted DNE_IOCTL DeviceIoControl request to the \\.\DNE device interface.

CVE-2008-5107 citrix vulnerability CVSS: 1.9 17 Nov 2008, 18:18 UTC

The installation process for Citrix Presentation Server 4.5 and Desktop Server 1.0, when MSI logging is enabled, stores database credentials in MSI log files, which allows local users to obtain these credentials by reading the log files.

CVE-2008-4676 citrix vulnerability CVSS: 6.8 22 Oct 2008, 10:30 UTC

Unspecified vulnerability in Citrix XenApp (formerly Presentation Server) 4.5 Feature Pack 1 and earlier, Presentation Server 4.0, and Access Essentials 1.0, 1.5, and 2.0 allows local users to gain privileges via unknown attack vectors related to creating an unspecified file. NOTE: this might be the same issue as CVE-2008-3485, but the vendor advisory is too vague to be certain.

CVE-2008-4405 citrix vulnerability CVSS: 7.2 03 Oct 2008, 17:41 UTC

xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM's write access within this tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue was originally reported as an issue in libvirt 0.3.3 and xenstore, but CVE is considering the core issue to be related to Xen.

CVE-2008-3485 citrix vulnerability CVSS: 7.2 06 Aug 2008, 17:41 UTC

Untrusted search path vulnerability in Citrix MetaFrame Presentation Server allows local users to gain privileges via a malicious icabar.exe placed in the search path.

CVE-2008-3253 citrix vulnerability CVSS: 4.3 22 Jul 2008, 16:41 UTC

Cross-site scripting (XSS) vulnerability in the XenAPI HTTP interfaces in Citrix XenServer Express, Standard, and Enterprise Edition 4.1.0; Citrix XenServer Dell Edition (Express and Enterprise) 4.1.0; and HP integrated Citrix XenServer (Select and Enterprise) 4.1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2008-2528 citrix vulnerability CVSS: 10.0 03 Jun 2008, 15:32 UTC

Unspecified vulnerability in Citrix Access Gateway Standard Edition 4.5.7 and earlier and Advanced Edition 4.5 HF2 and earlier allows attackers to bypass authentication and gain "access to network resources" via unspecified vectors.

CVE-2008-2300 citrix vulnerability CVSS: 6.5 18 May 2008, 14:20 UTC

Unspecified vulnerability in Citrix Presentation Server 4.5 and earlier, Citrix Access Essentials 2.0 and earlier, and Citrix Desktop Server 1.0 allows remote authenticated users to access unauthorized desktops via unknown attack vectors.

CVE-2008-2299 citrix vulnerability CVSS: 5.0 18 May 2008, 14:20 UTC

Unspecified vulnerability in SecureICA and ICA Basic encryption of Citrix Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 can cause clients to use weaker encryption settings than configured by the administrator, which might allow attackers to bypass intended restrictions.

CVE-2008-0356 citrix vulnerability CVSS: 10.0 18 Jan 2008, 22:00 UTC

Buffer overflow in the Independent Management Architecture (IMA) service in Citrix Presentation Server (MetaFrame Presentation Server) 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 allows remote attackers to execute arbitrary code via an invalid size value in a packet to TCP port 2512 or 2513.

CVE-2007-6477 citrix vulnerability CVSS: 4.3 20 Dec 2007, 20:46 UTC

Cross-site scripting (XSS) vulnerability in the on-line help feature in Citrix Web Interface 2.0 and earlier, and NFuse, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2007-6267 citrix vulnerability CVSS: 2.1 07 Dec 2007, 11:46 UTC

Citrix EdgeSight 4.2 and 4.5 for Presentation Server, EdgeSight 4.2 and 4.5 for Endpoints, and EdgeSight for NetScaler 1.0 and 1.1 do not properly store database credentials in configuration files, which allows local users to obtain sensitive information.

CVE-2007-6193 citrix vulnerability CVSS: 5.0 30 Nov 2007, 01:46 UTC

The web management interface in Citrix NetScaler 8.0 build 47.8 stores the device's primary IP address in a cookie, which might allow remote attackers to obtain sensitive network configuration information if this address is not the same as the address being used by the web interface.

CVE-2007-6192 citrix vulnerability CVSS: 4.3 30 Nov 2007, 01:46 UTC

The web management interface in Citrix NetScaler 8.0 build 47.8 uses weak encryption (XOR of unpadded data) to store credentials within a cookie, which makes it easier for remote attackers to obtain cleartext credentials when a cookie is captured via a known-plaintext attack.

CVE-2007-6037 citrix vulnerability CVSS: 4.3 20 Nov 2007, 11:46 UTC

Cross-site scripting (XSS) vulnerability in ws/generic_api_call.pl in Citrix NetScaler 8.0 build 47.8 allows remote attackers to inject arbitrary web script or HTML via the standalone parameter and other unspecified parameters.

CVE-2007-0011 citrix vulnerability CVSS: 5.0 05 Nov 2007, 17:46 UTC

The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-dependent attackers to hijack sessions by reading "residual information", including the a referer log, browser history, or browser cache.

CVE-2007-4013 citrix vulnerability CVSS: 9.3 26 Jul 2007, 01:30 UTC

Multiple unspecified vulnerabilities in (1) Net6Helper.DLL (aka Net6Launcher Class) 4.5.2 and earlier, (2) npCtxCAO.dll (aka Citrix Endpoint Analysis Client) in a Firefox plugin directory, and (3) a second npCtxCAO.dll (aka CCAOControl Object) before 4.5.0.0 in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 have unknown impact and attack vectors, possibly related to buffer overflows. NOTE: vector 3 might overlap CVE-2007-3679.

CVE-2007-4017 citrix vulnerability CVSS: 7.6 26 Jul 2007, 01:30 UTC

Cross-site request forgery (CSRF) vulnerability in the web-based administration console in Citrix Access Gateway before firmware 4.5.5 allows remote attackers to perform certain configuration changes as administrators.

CVE-2007-4016 citrix vulnerability CVSS: 6.8 26 Jul 2007, 01:30 UTC

Unspecified vulnerability in the client components in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows attackers to execute arbitrary code via unspecified vectors.

CVE-2007-4018 citrix vulnerability CVSS: 6.8 26 Jul 2007, 01:30 UTC

Citrix Access Gateway Advanced Edition before firmware 4.5.5 allows attackers to redirect users to arbitrary web sites and conduct phishing attacks via unknown vectors.

CVE-2007-3679 citrix vulnerability CVSS: 4.3 25 Jul 2007, 17:30 UTC

The Citrix EPA ActiveX control (aka the "endpoint checking control" or CCAOControl Object) before 4.5.0.0 in npCtxCAO.dll in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows remote attackers to download and execute arbitrary programs onto a client system.

CVE-2007-3625 citrix vulnerability CVSS: 5.0 09 Jul 2007, 16:30 UTC

The Program Neighborhood Agent in Citrix Presentation Server Clients for 32-bit Windows before 10.100 allows remote attackers to cause a denial of service (agent exit) via a certain request that uses content redirection and a long pathname.

CVE-2007-2850 citrix vulnerability CVSS: 10.0 24 May 2007, 18:30 UTC

The Session Reliability Service (XTE) in Citrix MetaFrame Presentation Server 3.0, Presentation Server 4.0, and Access Essentials 1.0 and 1.5, allows remote attackers to bypass network security policies and connect to arbitrary TCP ports via a modified address:port string.

CVE-2007-1196 citrix vulnerability CVSS: 9.3 02 Mar 2007, 21:18 UTC

Unspecified vulnerability in Citrix Presentation Server Client for Windows before 10.0 allows remote web sites to execute arbitrary code via unspecified vectors, related to the implementation of ICA connectivity through proxy servers.

CVE-2007-0444 citrix vulnerability CVSS: 7.2 24 Jan 2007, 22:28 UTC

Stack-based buffer overflow in the print provider library (cpprov.dll) in Citrix Presentation Server 4.0, MetaFrame Presentation Server 3.0, and MetaFrame XP 1.0 allows local users and remote attackers to execute arbitrary code via long arguments to the (1) EnumPrintersW and (2) OpenPrinter functions.

CVE-2006-6572 citrix vulnerability CVSS: 6.5 15 Dec 2006, 11:28 UTC

Unspecified vulnerability in Citrix Advanced Access Control (AAC) Option 4.0, and Access Gateway 4.2 with Advanced Access Control 4.2, before 20061114, when the Browser-Only access feature is enabled, allows remote authenticated users to bypass access policies via a certain login method, a different issue than CVE-2006-4846. NOTE: some of these details are obtained from third party information.

CVE-2006-6573 citrix vulnerability CVSS: 6.0 15 Dec 2006, 11:28 UTC

Unspecified vulnerability in Citrix Access Gateway 4.5 Advanced Edition, and 4.2 with Advanced Access Control (AAC) 4.2, when deployed on the Access Gateway appliance 4.2 through 4.2.2 allows remote authenticated users to "gain access to data" and obtain sensitive information via unspecified vectors.

CVE-2006-6334 citrix vulnerability CVSS: 6.8 08 Dec 2006, 01:28 UTC

Heap-based buffer overflow in the SendChannelData function in wfica.ocx in Citrix Presentation Server Client before 9.230 for Windows allows remote malicious web sites to execute arbitrary code via a DataSize parameter that is less than the length of the Data buffer.

CVE-2006-5821 citrix vulnerability CVSS: 7.5 10 Nov 2006, 23:07 UTC

Heap-based buffer overflow in the IMA_SECURE_DecryptData1 function in ImaSystem.dll for Citrix MetaFrame XP 1.0 and 2.0, and Presentation Server 3.0 and 4.0, allows remote attackers to execute arbitrary code via requests to the Independent Management Architecture (IMA) service (ImaSrv.exe) with invalid size values that trigger the overflow during decryption.

CVE-2006-5861 citrix vulnerability CVSS: 5.0 10 Nov 2006, 23:07 UTC

The Independent Management Architecture (IMA) service (ImaSrv.exe) in Citrix MetaFrame XP 1.0 and 2.0, and Presentation Server 3.0 and 4.0, allows remote attackers to cause a denial of service (service exit) via a crafted packet that causes the service to access an unmapped memory address and triggers an unhandled exception.

CVE-2006-4846 citrix vulnerability CVSS: 5.1 19 Sep 2006, 01:07 UTC

Unspecified vulnerability in Citrix Access Gateway with Advanced Access Control (AAC) 4.2 before 20060914, when AAC is configured to use LDAP authentication, allows remote attackers to bypass authentication via unknown vectors.

CVE-2006-3779 citrix vulnerability CVSS: 6.5 24 Jul 2006, 12:19 UTC

Citrix MetaFrame up to XP 1.0 Feature 1, except when running on Windows Server 2003, installs a registry key with an insecure ACL, which allows remote authenticated users to gain privileges.

CVE-2005-4412 citrix vulnerability CVSS: 2.1 20 Dec 2005, 11:03 UTC

Citrix Program Neighborhood client before 9.150 caches the user password in plaintext in the GUI while asterisks are used to visually obfuscate the password, which allows attackers with access to the session to obtain the password by using a tool to directly access the field.

CVE-2005-3652 citrix vulnerability CVSS: 7.5 16 Dec 2005, 23:03 UTC

Heap-based buffer overflow in Citrix Program Neighborhood client 9.0 and earlier allows remote attackers to execute arbitrary code via a long name value in an Application Set response.

CVE-2005-3971 citrix vulnerability CVSS: 4.3 03 Dec 2005, 19:03 UTC

Cross-site scripting (XSS) vulnerability in the login form in Citrix MetaFrame Secure Access Manager 2.0 through 2.2 and NFuse Elite 1.0 allows remote attackers to inject arbitrary web script or HTML via the username field.

CVE-2005-3134 citrix vulnerability CVSS: 7.5 04 Oct 2005, 22:02 UTC

Citrix Metaframe Presentation Server 3.0 and 4.0 allows remote attackers to bypass policy restrictions by downloading the launch.ica file and changing the client device name (ClientName).

CVE-2005-0822 citrix vulnerability CVSS: 2.1 02 May 2005, 04:00 UTC

Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is not allowed by policy.

CVE-2004-1902 citrix vulnerability CVSS: 2.1 31 Dec 2004, 05:00 UTC

The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information.

CVE-2004-1078 citrix vulnerability CVSS: 7.5 26 Apr 2004, 04:00 UTC

Stack-based buffer overflow in the client for Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and Citrix MetaFrame Presentation Server client for WinCE before 8.33 allows remote attackers to execute arbitrary code via a long cached icon filename in the InName XML element.

CVE-2004-1077 citrix vulnerability CVSS: 5.0 26 Apr 2004, 04:00 UTC

Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and MetaFrame Presentation Server client for WinCE before 8.33 allows remote servers to create arbitrary shortcuts on the client via a full UNC path in the AppInStartmenu directive.

CVE-2003-1157 citrix vulnerability CVSS: 4.3 31 Dec 2003, 05:00 UTC

Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web script or HTML via the NFuse_Message parameter.

CVE-2002-2426 citrix vulnerability CVSS: 4.3 31 Dec 2002, 05:00 UTC

Cross-site request forgery (CSRF) vulnerability in Citrix Presentation Server 4.0 and 4.5, MetaFrame Presentation Server 3.0, and Access Essentials 1.0 through 2.0 allows remote attackers to execute arbitrary published applications, and possibly other programs, as authenticated users via the InitialProgram key in an ICA connection. NOTE: some of these details are obtained from third party information.

CVE-2002-0504 citrix vulnerability CVSS: 7.5 12 Aug 2002, 04:00 UTC

Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp.

CVE-2002-0502 citrix vulnerability CVSS: 5.0 12 Aug 2002, 04:00 UTC

Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page.

CVE-2002-0503 citrix vulnerability CVSS: 5.0 12 Aug 2002, 04:00 UTC

Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter.

CVE-2002-0301 citrix vulnerability CVSS: 5.0 31 May 2002, 04:00 UTC

Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters.

CVE-2001-1192 citrix vulnerability CVSS: 7.5 13 Dec 2001, 05:00 UTC

Citrix Independent Computing Architecture (ICA) Client for Windows 6.1 allows remote malicious web sites to execute arbitrary code via a .ICA file, which is downloaded and automatically executed by the client.

CVE-2001-0716 citrix vulnerability CVSS: 5.0 06 Dec 2001, 05:00 UTC

Citrix MetaFrame 1.8 Server with Service Pack 3, and XP Server Service Pack 1 and earlier, allows remote attackers to cause a denial of service (crash) via a large number of incomplete connections to the server.

CVE-2001-0908 citrix vulnerability CVSS: 7.5 21 Nov 2001, 05:00 UTC

CITRIX Metaframe 1.8 logs the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through Network Address Translation (NAT).

CVE-2001-0760 citrix vulnerability CVSS: 5.0 18 Oct 2001, 04:00 UTC

Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not provide the session field.

CVE-2000-0244 citrix vulnerability CVSS: 10.0 29 Mar 2000, 05:00 UTC

The Citrix ICA (Independent Computing Architecture) protocol uses weak encryption (XOR) for user authentication.