imPC@ndo EN

Vulnerabilità Citrix

393 CVE

CVE-2020-8200
Media 6.5

Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.

citrix storefront_server
0.01EPSS
CVE-2008-5882
Alta 7.5

SQL injection vulnerability in login.asp in Citrix Application Gateway - Broadcast Server (BCS) before 6.1, as used by Avaya AG250 - Broadcast Server before 2.0 and possibly other products, allows remote attackers to execute arbitrary SQL commands via the txtU…

avaya broadcast_server · citrix broadcast_server
0.01EPSS
CVE-2007-4018
Media 6.8

Citrix Access Gateway Advanced Edition before firmware 4.5.5 allows attackers to redirect users to arbitrary web sites and conduct phishing attacks via unknown vectors.

citrix access_gateway
0.01EPSS
CVE-2006-3779
Media 6.5

Citrix MetaFrame up to XP 1.0 Feature 1, except when running on Windows Server 2003, installs a registry key with an insecure ACL, which allows remote authenticated users to gain privileges.

citrix metaframe · citrix metaframe_presentation_server · citrix presentation_server
0.01EPSS
CVE-2007-6477
Media 4.3

Cross-site scripting (XSS) vulnerability in the on-line help feature in Citrix Web Interface 2.0 and earlier, and NFuse, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

citrix web_interface
0.01EPSS
CVE-2016-1571
Media 6.3

The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address in an…

citrix xenserver · xen xen
0.01EPSS
CVE-2016-6877
Media 5.3

Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving the HTTP Host header and a cached page. NOTE: the vendor reports "our internal analysis of this issue concluded that this was no…

citrix xenmobile_server
0.01EPSS
CVE-2020-8258
Alta 7.5

Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, allows an attacker to modify arbitrary files.

citrix gateway_plug-in
0.01EPSS
CVE-2019-17366
Alta 8.8

Citrix Application Delivery Management (ADM) 12.1 before build 54.13 has Incorrect Access Control.

citrix application_delivery_management
0.01EPSS
CVE-2018-10648
Critica 9.8

There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

citrix xenmobile_server
0.01EPSS
CVE-2020-8190
Alta 7.5

Incorrect file permissions in Citrix ADC and Citrix Gateway before versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows privilege escalation.

citrix application_delivery_controller_firmware · citrix gateway_firmware · citrix netscaler_gateway_firmware
0.01EPSS
CVE-2019-7218
Media 5.9

Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline victim's otp physical token or virtual app (like google authenticator) is able to bypass the first authenticati…

citrix sharefile
0.01EPSS
CVE-2018-10654
Alta 8.1

There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

citrix xenmobile_server
0.01EPSS
CVE-2022-27510
Critica 9.8

Unauthorized access to Gateway user capabilities

citrix application_delivery_controller_firmware · citrix gateway
0.01EPSS
CVE-2014-1899
Media 4.3

Cross-site scripting (XSS) vulnerability in Citrix NetScaler Gateway (formerly Citrix Access Gateway Enterprise Edition) 9.x before 9.3.66.5 and 10.x before 10.1.123.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

citrix netscaler_access_gateway · citrix netscaler_access_gateway_firmware
0.01EPSS
CVE-2018-6811
Media 6.1

Multiple cross-site scripting (XSS) vulnerabilities in Citrix NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to inject arbitrary web script or HTML via the Citrix NetScaler interface.

citrix netscaler_application_delivery_controller_firmware · citrix netscaler_gateway_firmware
0.01EPSS
CVE-2004-1077
Media 5.0

Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and MetaFrame Presentation Server client for WinCE before 8.33 allows remote servers to create arbitrary shortcuts on the client via a full UNC path in the AppInStartmenu directive.

citrix metaframe_client · citrix program_neighborhood_agent
0.01EPSS
CVE-2018-10652
Alta 7.5

There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3.

citrix xenmobile_server
0.01EPSS
CVE-2009-3758
Alta 7.5

SQL injection vulnerability in login.php in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party inform…

citrix xencenterweb
0.01EPSS
CVE-2008-5121
Alta 7.2

dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, and (3) SafeNet SoftRemote and HighAssurance Remote, allows local users to gain privileges via a crafted DNE_IO…

citrix deterministic_network_enhancer
0.01EPSS
CVE-2007-6193
Media 5.0

The web management interface in Citrix NetScaler 8.0 build 47.8 stores the device's primary IP address in a cookie, which might allow remote attackers to obtain sensitive network configuration information if this address is not the same as the address being us…

citrix netscaler
0.01EPSS
CVE-2018-16969
Media 4.3

Citrix ShareFile StorageZones Controller before 5.4.2 has Information Exposure Through an Error Message.

citrix sharefile_storagezones_controller
0.01EPSS
CVE-2017-5573
Media 4.9

An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated read-only administrator can cancel tasks of other administrators.

citrix xenserver
0.01EPSS
CVE-2017-5572
Media 6.5

An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated read-only administrator can corrupt the host database.

citrix xenserver
0.01EPSS
CVE-2021-22891
Critica 9.8

A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.10.1 and 5.11.18 may allow unauthenticated remote compromise of the Storage Zones Controller.

citrix sharefile_storagezones_controller
0.01EPSS