Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Citrix Subscribe
Total 380 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-4700 1 Citrix 1 Xendesktop 2018-12-18 4.9 MEDIUM N/A
Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user's desktop via unspecified vectors.
CVE-2018-17447 1 Citrix 2 Netscaler Sd-wan, Sd-wan 2018-12-17 5.0 MEDIUM 7.5 HIGH
An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.
CVE-2018-18517 1 Citrix 1 Netscaler Gateway Firmware 2018-12-06 3.5 LOW 4.8 MEDIUM
Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x before 12.1.49.1 has XSS.
CVE-2018-17444 1 Citrix 2 Netscaler Sd-wan, Sd-wan 2018-12-04 5.0 MEDIUM 7.5 HIGH
A Directory Traversal issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.
CVE-2018-17446 1 Citrix 2 Netscaler Sd-wan, Sd-wan 2018-12-04 7.5 HIGH 9.8 CRITICAL
A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.
CVE-2018-16968 1 Citrix 1 Sharefile Storagezones Controller 2018-11-23 3.5 LOW 3.1 LOW
Citrix ShareFile StorageZones Controller before 5.4.2 allows Directory Traversal.
CVE-2018-16969 1 Citrix 1 Sharefile Storagezones Controller 2018-11-23 4.0 MEDIUM 4.3 MEDIUM
Citrix ShareFile StorageZones Controller before 5.4.2 has Information Exposure Through an Error Message.
CVE-2016-1571 2 Citrix, Xen 2 Xenserver, Xen 2018-10-30 4.7 MEDIUM 6.3 MEDIUM
The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address in an INVVPID instruction, which triggers a hypervisor bug check.
CVE-2008-5882 2 Avaya, Citrix 4 Ag250, Broadcast Server, Application Gateway For Avaya and 1 more 2018-10-30 7.5 HIGH N/A
SQL injection vulnerability in login.asp in Citrix Application Gateway - Broadcast Server (BCS) before 6.1, as used by Avaya AG250 - Broadcast Server before 2.0 and possibly other products, allows remote attackers to execute arbitrary SQL commands via the txtUID parameter.
CVE-2018-14007 1 Citrix 1 Xenserver 2018-10-23 10.0 HIGH 9.8 CRITICAL
Citrix XenServer 7.1 and newer allows Directory Traversal.
CVE-2006-6334 1 Citrix 1 Presentation Server Client 2018-10-17 6.8 MEDIUM N/A
Heap-based buffer overflow in the SendChannelData function in wfica.ocx in Citrix Presentation Server Client before 9.230 for Windows allows remote malicious web sites to execute arbitrary code via a DataSize parameter that is less than the length of the Data buffer.
CVE-2006-5821 1 Citrix 2 Metaframe, Metaframe Presentation Server 2018-10-17 7.5 HIGH N/A
Heap-based buffer overflow in the IMA_SECURE_DecryptData1 function in ImaSystem.dll for Citrix MetaFrame XP 1.0 and 2.0, and Presentation Server 3.0 and 4.0, allows remote attackers to execute arbitrary code via requests to the Independent Management Architecture (IMA) service (ImaSrv.exe) with invalid size values that trigger the overflow during decryption.
CVE-2007-0444 1 Citrix 2 Metaframe, Metaframe Presentation Server 2018-10-16 7.2 HIGH N/A
Stack-based buffer overflow in the print provider library (cpprov.dll) in Citrix Presentation Server 4.0, MetaFrame Presentation Server 3.0, and MetaFrame XP 1.0 allows local users and remote attackers to execute arbitrary code via long arguments to the (1) EnumPrintersW and (2) OpenPrinter functions.
CVE-2007-0011 1 Citrix 1 Access Gateway 2018-10-16 5.0 MEDIUM N/A
The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-dependent attackers to hijack sessions by reading "residual information", including the a referer log, browser history, or browser cache.
CVE-2008-0356 1 Citrix 4 Access Essentials, Desktop Server, Metaframe Presentation Server and 1 more 2018-10-15 10.0 HIGH N/A
Buffer overflow in the Independent Management Architecture (IMA) service in Citrix Presentation Server (MetaFrame Presentation Server) 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 allows remote attackers to execute arbitrary code via an invalid size value in a packet to TCP port 2512 or 2513.
CVE-2007-6192 1 Citrix 1 Netscaler 2018-10-15 4.3 MEDIUM N/A
The web management interface in Citrix NetScaler 8.0 build 47.8 uses weak encryption (XOR of unpadded data) to store credentials within a cookie, which makes it easier for remote attackers to obtain cleartext credentials when a cookie is captured via a known-plaintext attack.
CVE-2007-6193 1 Citrix 1 Netscaler 2018-10-15 5.0 MEDIUM N/A
The web management interface in Citrix NetScaler 8.0 build 47.8 stores the device's primary IP address in a cookie, which might allow remote attackers to obtain sensitive network configuration information if this address is not the same as the address being used by the web interface.
CVE-2007-6037 1 Citrix 1 Netscaler 2018-10-15 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in ws/generic_api_call.pl in Citrix NetScaler 8.0 build 47.8 allows remote attackers to inject arbitrary web script or HTML via the standalone parameter and other unspecified parameters.
CVE-2007-3679 1 Citrix 1 Access Gateway 2018-10-15 4.3 MEDIUM N/A
The Citrix EPA ActiveX control (aka the "endpoint checking control" or CCAOControl Object) before 4.5.0.0 in npCtxCAO.dll in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows remote attackers to download and execute arbitrary programs onto a client system.
CVE-2008-3485 1 Citrix 2 Metaframe Presentation Server, Xp 2018-10-11 7.2 HIGH N/A
Untrusted search path vulnerability in Citrix MetaFrame Presentation Server allows local users to gain privileges via a malicious icabar.exe placed in the search path.