Lucene search

K

Citrix Security Vulnerabilities

cve
cve

CVE-2010-4515

Cross-site scripting (XSS) vulnerability in Citrix Web Interface 5.0, 5.1, and 5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-6477 and...

5.7AI Score

0.002EPSS

2010-12-09 09:00 PM
20
cve
cve

CVE-2010-3699

The backend driver in Xen 3.x allows guest OS users to cause a denial of service via a kernel thread leak, which prevents the device and guest OS from being shut down or create a zombie domain, causes a hang in zenwatch, or prevents unspecified xm commands from working properly, related to (1)...

7.3AI Score

0.001EPSS

2010-12-08 08:00 PM
50
cve
cve

CVE-2010-2990

Citrix Online Plug-in for Windows for XenApp & XenDesktop before 11.2, Citrix Online Plug-in for Mac for XenApp & XenDesktop before 11.0, Citrix ICA Client for Linux before 11.100, Citrix ICA Client for Solaris before 8.63, and Citrix Receiver for Windows Mobile before 11.5 allow remote attackers.....

7.7AI Score

0.027EPSS

2010-08-11 08:00 PM
44
cve
cve

CVE-2009-3936

Unspecified vulnerability in Citrix Online Plug-in for Windows 11.0.x before 11.0.150 and 11.x before 11.2, Online Plug-in for Mac before 11.0, Receiver for iPhone before 1.0.3, and ICA Java, Mac, UNIX, and Windows Clients for XenApp and XenDesktop allows remote attackers to impersonate the...

9.6AI Score

0.004EPSS

2009-11-13 04:30 PM
33
cve
cve

CVE-2009-3757

Multiple cross-site scripting (XSS) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to config/edituser.php; (2) location, (3) sessionid, and (4) vmname parameters to...

5.8AI Score

0.005EPSS

2009-10-22 05:30 PM
16
cve
cve

CVE-2009-3758

SQL injection vulnerability in login.php in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party...

8.4AI Score

0.005EPSS

2009-10-22 05:30 PM
21
cve
cve

CVE-2009-3760

Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to inject arbitrary PHP code into include/config.ini.php via the pool1 parameter. NOTE: some of these details are obtained from third party.....

7.2AI Score

0.141EPSS

2009-10-22 05:30 PM
17
cve
cve

CVE-2009-2214

The Secure Gateway service in Citrix Secure Gateway 3.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an unspecified...

6.8AI Score

0.024EPSS

2009-06-25 11:14 PM
20
cve
cve

CVE-2008-6830

The disconnection feature in Citrix Web Interface 5.0 and 5.0.1 for Java Application Servers does not properly terminate a user's web interface session, which allows attackers with access to the same browser instance to gain access to the user's Web Interface session. NOTE: the attacker must also.....

6.9AI Score

0.003EPSS

2009-06-08 07:30 PM
20
cve
cve

CVE-2008-6561

Citrix Presentation Server Client for Windows before 10.200 does not clear "credential information" from process memory in unspecified circumstances, which might allow local users to gain...

6.8AI Score

0.0004EPSS

2009-03-31 05:30 PM
19
cve
cve

CVE-2008-5882

SQL injection vulnerability in login.asp in Citrix Application Gateway - Broadcast Server (BCS) before 6.1, as used by Avaya AG250 - Broadcast Server before 2.0 and possibly other products, allows remote attackers to execute arbitrary SQL commands via the txtUID...

8.7AI Score

0.008EPSS

2009-01-09 06:30 PM
24
cve
cve

CVE-2008-5716

xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3)...

6.7AI Score

0.001EPSS

2008-12-24 06:29 PM
22
cve
cve

CVE-2008-5121

dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, and (3) SafeNet SoftRemote and HighAssurance Remote, allows local users to gain privileges via a crafted DNE_IOCTL DeviceIoControl request to the...

6.5AI Score

0.0004EPSS

2008-11-18 12:30 AM
32
cve
cve

CVE-2008-5107

The installation process for Citrix Presentation Server 4.5 and Desktop Server 1.0, when MSI logging is enabled, stores database credentials in MSI log files, which allows local users to obtain these credentials by reading the log...

6.2AI Score

0.0004EPSS

2008-11-17 06:18 PM
29
cve
cve

CVE-2008-4676

Unspecified vulnerability in Citrix XenApp (formerly Presentation Server) 4.5 Feature Pack 1 and earlier, Presentation Server 4.0, and Access Essentials 1.0, 1.5, and 2.0 allows local users to gain privileges via unknown attack vectors related to creating an unspecified file. NOTE: this might be...

6.3AI Score

0.0004EPSS

2008-10-22 10:30 AM
23
cve
cve

CVE-2008-4405

xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM's write access within this tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1)...

7.8AI Score

0.001EPSS

2008-10-03 05:41 PM
23
cve
cve

CVE-2008-3485

Untrusted search path vulnerability in Citrix MetaFrame Presentation Server allows local users to gain privileges via a malicious icabar.exe placed in the search...

6.3AI Score

0.0004EPSS

2008-08-06 05:41 PM
20
cve
cve

CVE-2008-3253

Cross-site scripting (XSS) vulnerability in the XenAPI HTTP interfaces in Citrix XenServer Express, Standard, and Enterprise Edition 4.1.0; Citrix XenServer Dell Edition (Express and Enterprise) 4.1.0; and HP integrated Citrix XenServer (Select and Enterprise) 4.1.0 allows remote attackers to...

5.7AI Score

0.002EPSS

2008-07-22 04:41 PM
19
cve
cve

CVE-2008-2528

Unspecified vulnerability in Citrix Access Gateway Standard Edition 4.5.7 and earlier and Advanced Edition 4.5 HF2 and earlier allows attackers to bypass authentication and gain "access to network resources" via unspecified...

6.9AI Score

0.004EPSS

2008-06-03 03:32 PM
26
cve
cve

CVE-2008-2299

Unspecified vulnerability in SecureICA and ICA Basic encryption of Citrix Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 can cause clients to use weaker encryption settings than configured by the administrator, which might allow attackers to bypass...

6.5AI Score

0.002EPSS

2008-05-18 02:20 PM
24
cve
cve

CVE-2008-2300

Unspecified vulnerability in Citrix Presentation Server 4.5 and earlier, Citrix Access Essentials 2.0 and earlier, and Citrix Desktop Server 1.0 allows remote authenticated users to access unauthorized desktops via unknown attack...

6.2AI Score

0.004EPSS

2008-05-18 02:20 PM
26
cve
cve

CVE-2008-0356

Buffer overflow in the Independent Management Architecture (IMA) service in Citrix Presentation Server (MetaFrame Presentation Server) 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 allows remote attackers to execute arbitrary code via an invalid size value in a packet.....

7.8AI Score

0.84EPSS

2008-01-18 10:00 PM
30
cve
cve

CVE-2007-6477

Cross-site scripting (XSS) vulnerability in the on-line help feature in Citrix Web Interface 2.0 and earlier, and NFuse, allows remote attackers to inject arbitrary web script or HTML via unspecified...

5.6AI Score

0.002EPSS

2007-12-20 08:46 PM
26
cve
cve

CVE-2007-6267

Citrix EdgeSight 4.2 and 4.5 for Presentation Server, EdgeSight 4.2 and 4.5 for Endpoints, and EdgeSight for NetScaler 1.0 and 1.1 do not properly store database credentials in configuration files, which allows local users to obtain sensitive...

6.1AI Score

0.0004EPSS

2007-12-07 11:46 AM
21
cve
cve

CVE-2007-6193

The web management interface in Citrix NetScaler 8.0 build 47.8 stores the device's primary IP address in a cookie, which might allow remote attackers to obtain sensitive network configuration information if this address is not the same as the address being used by the web...

6.1AI Score

0.003EPSS

2007-11-30 01:46 AM
28
cve
cve

CVE-2007-6192

The web management interface in Citrix NetScaler 8.0 build 47.8 uses weak encryption (XOR of unpadded data) to store credentials within a cookie, which makes it easier for remote attackers to obtain cleartext credentials when a cookie is captured via a known-plaintext...

6.4AI Score

0.002EPSS

2007-11-30 01:46 AM
23
cve
cve

CVE-2007-6037

Cross-site scripting (XSS) vulnerability in ws/generic_api_call.pl in Citrix NetScaler 8.0 build 47.8 allows remote attackers to inject arbitrary web script or HTML via the standalone parameter and other unspecified...

5.6AI Score

0.004EPSS

2007-11-20 11:46 AM
21
cve
cve

CVE-2002-2426

Cross-site request forgery (CSRF) vulnerability in Citrix Presentation Server 4.0 and 4.5, MetaFrame Presentation Server 3.0, and Access Essentials 1.0 through 2.0 allows remote attackers to execute arbitrary published applications, and possibly other programs, as authenticated users via the...

7.9AI Score

0.003EPSS

2007-11-20 12:00 AM
20
cve
cve

CVE-2007-0011

The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-dependent attackers to hijack sessions by reading "residual information", including the a referer log, browser history, or...

6.3AI Score

0.011EPSS

2007-11-05 05:46 PM
26
cve
cve

CVE-2007-4016

Unspecified vulnerability in the client components in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows attackers to execute arbitrary code via unspecified...

7.6AI Score

0.009EPSS

2007-07-26 01:30 AM
21
cve
cve

CVE-2007-4013

Multiple unspecified vulnerabilities in (1) Net6Helper.DLL (aka Net6Launcher Class) 4.5.2 and earlier, (2) npCtxCAO.dll (aka Citrix Endpoint Analysis Client) in a Firefox plugin directory, and (3) a second npCtxCAO.dll (aka CCAOControl Object) before 4.5.0.0 in Citrix Access Gateway Standard...

6.8AI Score

0.011EPSS

2007-07-26 01:30 AM
19
cve
cve

CVE-2007-4017

Cross-site request forgery (CSRF) vulnerability in the web-based administration console in Citrix Access Gateway before firmware 4.5.5 allows remote attackers to perform certain configuration changes as...

7AI Score

0.024EPSS

2007-07-26 01:30 AM
26
cve
cve

CVE-2007-4018

Citrix Access Gateway Advanced Edition before firmware 4.5.5 allows attackers to redirect users to arbitrary web sites and conduct phishing attacks via unknown...

6.7AI Score

0.007EPSS

2007-07-26 01:30 AM
22
cve
cve

CVE-2007-3679

The Citrix EPA ActiveX control (aka the "endpoint checking control" or CCAOControl Object) before 4.5.0.0 in npCtxCAO.dll in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows remote attackers to download and execute arbitrary programs onto a client...

7.2AI Score

0.01EPSS

2007-07-25 05:30 PM
24
cve
cve

CVE-2007-3625

The Program Neighborhood Agent in Citrix Presentation Server Clients for 32-bit Windows before 10.100 allows remote attackers to cause a denial of service (agent exit) via a certain request that uses content redirection and a long...

6.6AI Score

0.045EPSS

2007-07-09 04:30 PM
29
cve
cve

CVE-2007-2850

The Session Reliability Service (XTE) in Citrix MetaFrame Presentation Server 3.0, Presentation Server 4.0, and Access Essentials 1.0 and 1.5, allows remote attackers to bypass network security policies and connect to arbitrary TCP ports via a modified address:port...

6.8AI Score

0.063EPSS

2007-05-24 06:30 PM
25
cve
cve

CVE-2007-1196

Unspecified vulnerability in Citrix Presentation Server Client for Windows before 10.0 allows remote web sites to execute arbitrary code via unspecified vectors, related to the implementation of ICA connectivity through proxy...

7.8AI Score

0.014EPSS

2007-03-02 09:18 PM
26
cve
cve

CVE-2007-0444

Stack-based buffer overflow in the print provider library (cpprov.dll) in Citrix Presentation Server 4.0, MetaFrame Presentation Server 3.0, and MetaFrame XP 1.0 allows local users and remote attackers to execute arbitrary code via long arguments to the (1) EnumPrintersW and (2) OpenPrinter...

7.7AI Score

0.01EPSS

2007-01-24 10:28 PM
21
cve
cve

CVE-2006-6573

Unspecified vulnerability in Citrix Access Gateway 4.5 Advanced Edition, and 4.2 with Advanced Access Control (AAC) 4.2, when deployed on the Access Gateway appliance 4.2 through 4.2.2 allows remote authenticated users to "gain access to data" and obtain sensitive information via unspecified...

5.8AI Score

0.003EPSS

2006-12-15 11:28 AM
25
cve
cve

CVE-2006-6572

Unspecified vulnerability in Citrix Advanced Access Control (AAC) Option 4.0, and Access Gateway 4.2 with Advanced Access Control 4.2, before 20061114, when the Browser-Only access feature is enabled, allows remote authenticated users to bypass access policies via a certain login method, a...

6.1AI Score

0.073EPSS

2006-12-15 11:28 AM
23
cve
cve

CVE-2006-6334

Heap-based buffer overflow in the SendChannelData function in wfica.ocx in Citrix Presentation Server Client before 9.230 for Windows allows remote malicious web sites to execute arbitrary code via a DataSize parameter that is less than the length of the Data...

7.7AI Score

0.134EPSS

2006-12-08 01:28 AM
20
cve
cve

CVE-2006-5821

Heap-based buffer overflow in the IMA_SECURE_DecryptData1 function in ImaSystem.dll for Citrix MetaFrame XP 1.0 and 2.0, and Presentation Server 3.0 and 4.0, allows remote attackers to execute arbitrary code via requests to the Independent Management Architecture (IMA) service (ImaSrv.exe) with...

8.2AI Score

0.364EPSS

2006-11-10 11:07 PM
21
cve
cve

CVE-2006-5861

The Independent Management Architecture (IMA) service (ImaSrv.exe) in Citrix MetaFrame XP 1.0 and 2.0, and Presentation Server 3.0 and 4.0, allows remote attackers to cause a denial of service (service exit) via a crafted packet that causes the service to access an unmapped memory address and...

6.5AI Score

0.487EPSS

2006-11-10 11:07 PM
20
cve
cve

CVE-2006-4846

Unspecified vulnerability in Citrix Access Gateway with Advanced Access Control (AAC) 4.2 before 20060914, when AAC is configured to use LDAP authentication, allows remote attackers to bypass authentication via unknown...

6.8AI Score

0.073EPSS

2006-09-19 01:07 AM
21
cve
cve

CVE-2006-3779

Citrix MetaFrame up to XP 1.0 Feature 1, except when running on Windows Server 2003, installs a registry key with an insecure ACL, which allows remote authenticated users to gain...

6.8AI Score

0.005EPSS

2006-07-24 12:19 PM
18
cve
cve

CVE-2005-3652

Heap-based buffer overflow in Citrix Program Neighborhood client 9.0 and earlier allows remote attackers to execute arbitrary code via a long name value in an Application Set...

7.9AI Score

0.23EPSS

2005-12-16 11:03 PM
26
cve
cve

CVE-2005-3971

Cross-site scripting (XSS) vulnerability in the login form in Citrix MetaFrame Secure Access Manager 2.0 through 2.2 and NFuse Elite 1.0 allows remote attackers to inject arbitrary web script or HTML via the username...

5.9AI Score

0.004EPSS

2005-12-03 07:03 PM
24
cve
cve

CVE-2004-1902

The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive...

6.8AI Score

0.0004EPSS

2005-05-10 04:00 AM
25
cve
cve

CVE-2003-1157

Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web script or HTML via the NFuse_Message...

5.7AI Score

0.009EPSS

2005-05-10 04:00 AM
37
cve
cve

CVE-2005-0821

Unknown vulnerability in Citrix MetaFrame Conferencing Manager 3.0 allows conference members to bypass organizer restrictions to control the keyboard and...

6.9AI Score

0.004EPSS

2005-05-02 04:00 AM
23
Total number of security vulnerabilities411