58.483 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
Vulnerabilità Citrix
402 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2001-0760 | MED 5.0 | citrix nfuse Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not provide the session field. | 3,6% | — |
| CVE-2002-0502 | MED 5.0 | citrix nfuse Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page. | 3,6% | — |
| CVE-2007-6037 | MED 4.3 | citrix netscaler Cross-site scripting (XSS) vulnerability in ws/generic_api_call.pl in Citrix NetScaler 8.0 build 47.8 allows remote attackers to inject arbitrary web script or HTML via the standalone parameter and other unspecified parameters. | 3,6% | — |
| CVE-2018-17444 | HIGH 7.5 | citrix netscaler_sd-wan A Directory Traversal issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | 3,6% | — |
| CVE-2017-2620 | MED 5.5 | citrix xenserver Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw t | 3,6% | — |
| CVE-2020-8270 | HIGH 8.8 | citrix virtual_apps_and_desktops An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285871 and CTX285872, 7.15 LTSR CU6 hotfix CTX285341 and CTX285342 | 3,5% | — |
| CVE-2016-2071 | CRIT 9.8 | citrix netscaler Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, and 10.5.e before Build 59.1305.e allows remote attackers to gain privileges via unspecified NS Web GUI commands. | 3,4% | — |
| CVE-2017-5933 | MED 5.9 | citrix netscaler_application_delivery_controller_firmware Citrix NetScaler ADC and NetScaler Gateway 10.5 before Build 65.11, 11.0 before Build 69.12/69.123, and 11.1 before Build 51.21 randomly generates GCM nonces, which makes it marginally easier for remote attackers to obtain the GCM authentication key and spoof | 3,2% | — |
| CVE-2016-9679 | CRIT 9.8 | citrix provisioning_services Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code by overwriting a function pointer. | 3,2% | — |
| CVE-2015-5538 | HIGH 10.0 | citrix netscaler_application_delivery_controller_firmware Multiple unspecified vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 before Build 57.7, and 10.5e before Build 56.1505.e allow remote attackers to gain privileges via unknown vectors | 3,2% | — |
| CVE-2018-6186 | HIGH 8.8 | citrix netscaler Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/read_url URI by an authenticated attacker who has a webapp account. The attacker can gain access to the nsroot account, and execute remote commands with root privileges. | 3,1% | — |
| CVE-2016-9678 | CRIT 9.8 | citrix provisioning_services Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors. | 3,1% | — |
| CVE-2020-8300 | MED 6.5 | citrix application_delivery_controller_firmware Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note | 3,0% | — |
| CVE-2018-18013 | HIGH 7.8 | citrix xenmobile_server * Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If this service is supplied with raw serialised Java objects, it deserialises them back into Java objects in memory, giving rise to a | 2,9% | — |
| CVE-2014-1664 | MED 5.0 | citrix gotomeeting The Citrix GoToMeeting application 5.0.799.1238 for Android logs HTTP requests containing sensitive information, which allows attackers to obtain user IDs, meeting details, and authentication tokens via an application that reads the system log file. | 2,9% | — |
| CVE-2015-2838 | MED 6.8 | citrix netscaler Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary commands as nsroot via shell metacharacters in | 2,9% | — |
| CVE-2018-5314 | HIGH 7.5 | citrix netscaler_application_delivery_controller Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 500 | 2,8% | — |
| CVE-2021-44519 | HIGH 8.8 | citrix xenmobile_server In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution. | 2,8% | — |
| CVE-2007-2850 | HIGH 10.0 | citrix access_essentials The Session Reliability Service (XTE) in Citrix MetaFrame Presentation Server 3.0, Presentation Server 4.0, and Access Essentials 1.0 and 1.5, allows remote attackers to bypass network security policies and connect to arbitrary TCP ports via a modified address | 2,8% | — |
| CVE-2009-3760 | HIGH 7.5 | citrix xencenterweb Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to inject arbitrary PHP code into include/config.ini.php via the pool1 parameter. NOTE: some of these | 2,7% | — |
| CVE-2008-2528 | HIGH 10.0 | citrix access_gateway Unspecified vulnerability in Citrix Access Gateway Standard Edition 4.5.7 and earlier and Advanced Edition 4.5 HF2 and earlier allows attackers to bypass authentication and gain "access to network resources" via unspecified vectors. | 2,7% | — |
| CVE-2020-8283 | HIGH 8.8 | citrix virtual_apps_and_desktops An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9. | 2,7% | — |
| CVE-2020-8269 | HIGH 8.8 | citrix virtual_apps_and_desktops An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9 | 2,7% | — |
| CVE-2013-2757 | HIGH 7.5 | citrix cloudplatform Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C does not properly restrict access to VNC ports on the management network, which allows remote attackers to have unspecified impact via unknown vectors. | 2,7% | — |
| CVE-2020-10110 | MED 5.3 | citrix gateway_firmware Citrix Gateway 11.1, 12.0, and 12.1 allows Information Exposure Through Caching. NOTE: Citrix disputes this as not a vulnerability. There is no sensitive information disclosure through the cache headers on Citrix ADC. The "Via" header lists cache protocols and | 2,7% | — |