EN
58.483 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

Vulnerabilità Citrix

402 CVE

Vulnerabilità Citrix
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2014-3780 HIGH 7.5 citrix vdi-in-a-box Unspecified vulnerability in Citrix VDI-In-A-Box 5.3.x before 5.3.8 and 5.4.x before 5.4.4 allows remote attackers to bypass authentication via unspecified vectors, related to a Java servlet. 2,6% —
CVE-2023-3466 HIGH 8.3 citrix netscaler_application_delivery_controller Reflected Cross-Site Scripting (XSS) 2,6% —
CVE-2018-18571 CRIT 9.1 citrix xenmobile_server An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any Mobile Application Management (MAM) enrolled 2,6% —
CVE-2016-5302 CRIT 9.8 citrix xenserver Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a host by leveraging credentials for an Active Directory account. 2,6% —
CVE-2007-4017 HIGH 7.6 citrix access_gateway Cross-site request forgery (CSRF) vulnerability in the web-based administration console in Citrix Access Gateway before firmware 4.5.5 allows remote attackers to perform certain configuration changes as administrators. 2,5% —
CVE-2002-0503 MED 5.0 citrix nfuse Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter. 2,5% —
CVE-2020-8273 HIGH 8.8 citrix sd-wan Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8. 2,4% —
CVE-2017-14602 HIGH 7.2 citrix application_delivery_controller_firmware A vulnerability has been identified in the management interface of Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before build 135.18, 10.5 before build 66.9, 10.5e before build 60.7010.e, 11.0 before build 70.16, 11.1 before 2,4% —
CVE-2014-1663 MED 5.0 citrix xenmobile_device_manager Unspecified vulnerability in Citrix XenMobile Device Manager server (formerly Zenprise Device Manager server) 8.5, 8.6, and MDM 8.0.1 allows remote attackers to obtain sensitive information via unknown vectors. 2,3% —
CVE-2018-6808 HIGH 7.5 citrix netscaler_application_delivery_controller_firmware NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to download arbitrary files on the target system. 2,3% —
CVE-2000-0244 HIGH 10.0 citrix metaframe The Citrix ICA (Independent Computing Architecture) protocol uses weak encryption (XOR) for user authentication. 2,3% —
CVE-2019-6485 MED 5.9 citrix netscaler_application_delivery_controller_firmware Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 2,3% —
CVE-2009-3759 HIGH 8.8 citrix xencenterweb Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to hijack the authentication of administrators for (1) requests that change the password via the username para 2,3% —
CVE-2015-8555 HIGH 8.6 citrix xenserver Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains to obtain sensitive information from other domains via unspec 2,3% —
CVE-2007-4016 MED 6.8 citrix access_gateway Unspecified vulnerability in the client components in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows attackers to execute arbitrary code via unspecified vectors. 2,2% —
CVE-2018-17448 CRIT 9.8 citrix netscaler_sd-wan An Incorrect Access Control issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. 2,2% —
CVE-2016-6493 CRIT 9.8 citrix xenapp Citrix XenApp 6.x before 6.5 HRP07 and 7.x before 7.9 and Citrix XenDesktop before 7.9 might allow attackers to weaken an unspecified security mitigation via vectors related to memory permission. 2,2% —
CVE-2001-1192 HIGH 7.5 citrix ica_client Citrix Independent Computing Architecture (ICA) Client for Windows 6.1 allows remote malicious web sites to execute arbitrary code via a .ICA file, which is downloaded and automatically executed by the client. 2,2% —
CVE-2015-7999 HIGH 8.1 citrix command_center Multiple SQL injection vulnerabilities in the Administration Web UI servlets in Citrix Command Center before 5.1 Build 36.7 and 5.2 before Build 44.11 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors. 2,1% —
CVE-2009-2452 HIGH 10.0 citrix licensing Multiple unspecified vulnerabilities in Citrix Licensing 11.5 have unknown impact and attack vectors, related to "underlying components of the License Management Console." 2,1% —
CVE-2013-2601 HIGH 7.5 citrix xenclient_xt The NDVM in Citrix XenClient XT before 2.1.3 and 3.x before 3.1.4 allows remote attackers to execute arbitrary commands by using the UIVM to create a network connection. 2,1% —
CVE-2007-0011 MED 5.0 citrix access_gateway The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-dependent attackers to hijack sessions by reading "residual information", including the 2,1% —
CVE-2005-3134 HIGH 7.5 citrix metaframe Citrix Metaframe Presentation Server 3.0 and 4.0 allows remote attackers to bypass policy restrictions by downloading the launch.ica file and changing the client device name (ClientName). 2,1% —
CVE-2020-8207 HIGH 8.8 citrix workspace Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic updater service is running. 2,1% —
CVE-2002-0301 MED 5.0 citrix nfuse Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters. 2,0% —