Lucene search

K

Citrix Security Vulnerabilities

cve
cve

CVE-2023-0181

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a kernel mode layer handler, where memory permissions are not correctly checked, which may lead to denial of service and data...

7.1CVSS

6.5AI Score

0.0004EPSS

2023-04-01 05:15 AM
40
cve
cve

CVE-2022-34682

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a null-pointer dereference, which may lead to denial of...

5.5CVSS

5.7AI Score

0.0004EPSS

2022-12-30 11:15 PM
40
cve
cve

CVE-2022-42256

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow in index validation may lead to denial of service, information disclosure, or data...

7.8CVSS

7.6AI Score

0.0004EPSS

2022-12-30 11:15 PM
41
cve
cve

CVE-2022-34678

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged user can cause a null-pointer dereference, which may lead to denial of...

6.5CVSS

6.3AI Score

0.0004EPSS

2022-12-30 11:15 PM
48
cve
cve

CVE-2022-42261

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer overrun, which in turn may cause data tampering, information disclosure, or denial of...

7.8CVSS

7.6AI Score

0.0004EPSS

2022-12-30 11:15 PM
37
cve
cve

CVE-2022-42264

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause the use of an out-of-range pointer offset, which may lead to data tampering, data loss, information disclosure, or denial of...

7.8CVSS

7.3AI Score

0.0004EPSS

2022-12-30 11:15 PM
40
cve
cve

CVE-2022-34684

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an off-by-one error may lead to data tampering or information...

7.1CVSS

6.7AI Score

0.0004EPSS

2022-12-30 11:15 PM
38
cve
cve

CVE-2022-42254

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, data tampering, or information...

7.8CVSS

7.3AI Score

0.0004EPSS

2022-12-30 11:15 PM
47
cve
cve

CVE-2022-42259

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of...

5.5CVSS

6AI Score

0.0004EPSS

2022-12-30 11:15 PM
46
cve
cve

CVE-2022-42260

NVIDIA vGPU Display Driver for Linux guest contains a vulnerability in a D-Bus configuration file, where an unauthorized user in the guest VM can impact protected D-Bus endpoints, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data...

7.8CVSS

7.9AI Score

0.0004EPSS

2022-12-30 11:15 PM
46
cve
cve

CVE-2022-42263

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an Integer overflow may lead to denial of service or information...

7.1CVSS

6.9AI Score

0.0004EPSS

2022-12-30 11:15 PM
45
cve
cve

CVE-2022-42258

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of service, data tampering, or information...

7.3CVSS

7AI Score

0.0004EPSS

2022-12-30 11:15 PM
47
cve
cve

CVE-2022-34680

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an integer truncation can lead to an out-of-bounds read, which may lead to denial of...

5.5CVSS

5.8AI Score

0.0004EPSS

2022-12-30 11:15 PM
43
cve
cve

CVE-2022-34677

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause an integer to be truncated, which may lead to denial of service or data...

7.1CVSS

6.7AI Score

0.0004EPSS

2022-12-30 11:15 PM
50
cve
cve

CVE-2022-42257

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to information disclosure, data tampering or denial of...

7.3CVSS

7AI Score

0.0004EPSS

2022-12-30 11:15 PM
42
cve
cve

CVE-2022-34666

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a local user with basic capabilities can cause a null-pointer dereference, which may lead to denial of...

6.5CVSS

5.8AI Score

0.0004EPSS

2022-11-10 04:15 PM
39
8
cve
cve

CVE-2022-34674

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where a helper function maps more physical pages than were requested, which may lead to undefined behavior or an information...

6.8CVSS

6.2AI Score

0.0004EPSS

2022-12-30 11:15 PM
45
cve
cve

CVE-2022-34670

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause truncation errors when casting a primitive to a primitive of smaller size causes data to be lost in the conversion, which may lead to denial of service or...

7.8CVSS

7AI Score

0.0004EPSS

2022-12-30 11:15 PM
45
cve
cve

CVE-2022-26151

Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command...

7.2CVSS

7.4AI Score

0.002EPSS

2022-04-13 12:15 AM
69
2
cve
cve

CVE-2021-1062

NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input data length is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to...

7.1CVSS

7.2AI Score

0.0004EPSS

2021-01-08 03:15 PM
28
cve
cve

CVE-2021-1082

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), in which an input length is not validated, which may lead to information disclosure, tampering of data, or denial of service. vGPU version 12.x (prior to 12.2), version 11.x (prior to 11.4) and version 8.x...

7.8CVSS

7.1AI Score

0.0004EPSS

2021-04-29 07:15 PM
40
2
cve
cve

CVE-2021-1083

NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and Virtual GPU Manager (vGPU plugin), in which an input length is not validated, which may lead to information disclosure, tampering of data, or denial of service. This affects vGPU version 12.x (prior to 12.2) and...

7.8CVSS

7AI Score

0.0004EPSS

2021-04-29 07:15 PM
41
2
cve
cve

CVE-2021-1081

NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and Virtual GPU manager (vGPU plugin), in which an input length is not validated, which may lead to information disclosure, tampering of data, or denial of service. This affects vGPU version 12.x (prior to 12.2), version....

7.8CVSS

7AI Score

0.0004EPSS

2021-04-29 07:15 PM
41
2
cve
cve

CVE-2021-1058

NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input data size is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to...

7.1CVSS

7AI Score

0.0004EPSS

2021-01-08 03:15 PM
27
3
cve
cve

CVE-2023-3467

Privilege Escalation to root administrator...

8CVSS

8.7AI Score

0.0004EPSS

2023-07-19 07:15 PM
86
cve
cve

CVE-2023-3466

Reflected Cross-Site Scripting...

8.3CVSS

7.2AI Score

0.001EPSS

2023-07-19 07:15 PM
72
cve
cve

CVE-2023-24492

A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further...

9.6CVSS

8.6AI Score

0.002EPSS

2023-07-11 10:15 PM
39
cve
cve

CVE-2023-24491

A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate their local privileges to that of NT...

7.8CVSS

7.5AI Score

0.0004EPSS

2023-07-11 10:15 PM
26
cve
cve

CVE-2023-24490

Users with only access to launch VDA applications can launch an unauthorized...

6.3CVSS

4.6AI Score

0.0004EPSS

2023-07-10 10:15 PM
33
cve
cve

CVE-2023-24489

A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones...

9.8CVSS

9.3AI Score

0.974EPSS

2023-07-10 10:15 PM
266
In Wild
cve
cve

CVE-2022-27511

Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the device has...

8.1CVSS

8AI Score

0.003EPSS

2022-06-16 07:15 PM
110
8
cve
cve

CVE-2023-24486

A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is...

5.5CVSS

5.5AI Score

0.0004EPSS

2023-07-10 09:15 PM
1848
cve
cve

CVE-2023-25517

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest OS may be able to control resources for which it is not authorized, which may lead to information disclosure and data...

7.1CVSS

6.9AI Score

0.0004EPSS

2023-07-04 12:15 AM
6
cve
cve

CVE-2022-21825

An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege...

7.8CVSS

7.4AI Score

0.0004EPSS

2022-02-09 11:15 PM
46
cve
cve

CVE-2022-20717

A vulnerability in the NETCONF process of Cisco SD-WAN vEdge Routers could allow an authenticated, local attacker to cause an affected device to run out of memory, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient memory management when an affected device.....

5.5CVSS

5.3AI Score

0.0004EPSS

2022-04-15 03:15 PM
58
4
cve
cve

CVE-2022-34675

NVIDIA Display Driver for Linux contains a vulnerability in the Virtual GPU Manager, where it does not check the return value from a null-pointer dereference, which may lead to denial of...

5.5CVSS

6AI Score

0.0004EPSS

2022-12-30 11:15 PM
41
cve
cve

CVE-2023-0192

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer handler, where improper privilege management can lead to escalation of privileges and information...

7.8CVSS

7.5AI Score

0.0004EPSS

2023-04-01 05:15 AM
41
cve
cve

CVE-2023-0197

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious user in a guest VM can cause a NULL-pointer dereference, which may lead to denial of...

6.5CVSS

6.4AI Score

0.0004EPSS

2023-04-01 05:15 AM
28
cve
cve

CVE-2023-24484

A malicious user can cause log files to be written to a directory that they do not have permission to write...

5.5CVSS

5.9AI Score

0.0004EPSS

2023-02-16 06:15 PM
85
cve
cve

CVE-2023-24485

Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace...

7.8CVSS

7.7AI Score

0.0004EPSS

2023-02-16 06:15 PM
234
cve
cve

CVE-2023-24483

A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows...

7.8CVSS

7.4AI Score

0.0004EPSS

2023-02-16 06:15 PM
75
cve
cve

CVE-2016-3712

Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE...

5.5CVSS

6.4AI Score

0.001EPSS

2016-05-11 09:59 PM
73
4
cve
cve

CVE-2017-2615

Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or...

9.1CVSS

7.7AI Score

0.001EPSS

2018-07-03 01:29 AM
99
4
cve
cve

CVE-2022-27507

Authenticated denial of...

6.5CVSS

6.4AI Score

0.001EPSS

2023-01-26 09:15 PM
567
4
cve
cve

CVE-2022-27508

Unauthenticated denial of...

7.5CVSS

7.4AI Score

0.001EPSS

2023-01-26 09:15 PM
601
4
cve
cve

CVE-2019-19781

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory...

9.8CVSS

9.8AI Score

0.975EPSS

2019-12-27 02:15 PM
2149
In Wild
75
cve
cve

CVE-2022-42262

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer overrun, which in turn may cause data tampering, information disclosure, or denial of...

7.8CVSS

7.5AI Score

0.0004EPSS

2022-12-30 11:15 PM
37
cve
cve

CVE-2019-18177

In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688...

6.5CVSS

6.5AI Score

0.001EPSS

2022-12-26 09:15 PM
43
cve
cve

CVE-2021-44519

In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code...

8.8CVSS

9AI Score

0.011EPSS

2022-04-19 04:17 PM
96
cve
cve

CVE-2009-2453

Citrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Advanced Edition filters, which allows attackers to bypass intended access restrictions via unknown...

6.7AI Score

0.006EPSS

2022-10-03 04:24 PM
22
Total number of security vulnerabilities411