imPC@ndo EN

Vulnerabilità Citrix

393 CVE

CVE-2020-8253
Alta 7.5

Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 leads to the ability to access sensitive files.

citrix xenmobile_server
0.02EPSS
CVE-2014-4346
Media 4.3

Cross-site scripting (XSS) vulnerability in administration user interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) 10.1 before 10.1-126.12 allows remote attackers to inject arb…

citrix netscaler_access_gateway · citrix netscaler_access_gateway_firmware · citrix netscaler_application_delivery_controller · citrix netscaler_application_delivery_controller_firmware
0.02EPSS
CVE-2001-0716
Media 5.0

Citrix MetaFrame 1.8 Server with Service Pack 3, and XP Server Service Pack 1 and earlier, allows remote attackers to cause a denial of service (crash) via a large number of incomplete connections to the server.

citrix metaframe
0.02EPSS
CVE-2007-3679
Media 4.3

The Citrix EPA ActiveX control (aka the "endpoint checking control" or CCAOControl Object) before 4.5.0.0 in npCtxCAO.dll in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows remote attackers to download and execute…

citrix access_gateway
0.02EPSS
CVE-2013-6077
Media 5.8

Citrix XenDesktop 7.0, when upgraded from XenDesktop 5.x, does not properly enforce policy rule permissions, which allows remote attackers to bypass intended restrictions.

citrix xendesktop
0.02EPSS
CVE-2013-6941
Alta 10.0

Unspecified vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows users to "breakout" of the shell via unknown vectors.

citrix netscaler_application_delivery_controller_firmware
0.02EPSS
CVE-2013-2940
Alta 10.0

Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.

citrix cloudportal_services_manager
0.02EPSS
CVE-2013-2939
Alta 10.0

Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.

citrix cloudportal_services_manager
0.02EPSS
CVE-2013-2938
Alta 10.0

Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.

citrix cloudportal_services_manager
0.02EPSS
CVE-2013-2937
Alta 10.0

Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, related to debugging messages, a different vulnerability than other CVEs listed in CTX137162.

citrix cloudportal_services_manager
0.02EPSS
CVE-2013-2936
Alta 10.0

Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.

citrix cloudportal_services_manager
0.02EPSS
CVE-2013-2935
Alta 10.0

Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.

citrix cloudportal_services_manager
0.02EPSS
CVE-2013-2934
Alta 10.0

Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 does not properly restrict access to web services, which has unspecified impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.

citrix cloudportal_services_manager
0.02EPSS
CVE-2013-2933
Alta 10.0

Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.

citrix cloudportal_services_manager
0.02EPSS
CVE-2014-8495
Media 5.0

Citrix XenMobile MDX Toolkit before 9.0.4, when used to wrap iOS 8 applications, does not properly encrypt cached application data, which allows context-dependent attackers to obtain sensitive information by reading the cache.

citrix xenmobile
0.02EPSS
CVE-2020-8212
Critica 9.8

Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows access to privileged functionality.

citrix xenmobile_server
0.02EPSS
CVE-2020-8257
Critica 9.8

Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, lead to privilege escalation attacks

citrix gateway_plug-in
0.02EPSS
CVE-2013-6943
Media 5.0

Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to conduct an LDAP injection attack via vectors related to SSH and Web management usernames.

citrix netscaler_application_delivery_controller_firmware
0.02EPSS
CVE-2017-17549
Media 5.9

Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 allow remote attackers to obtain sensitive information from the backend client T…

citrix application_delivery_controller_firmware · citrix netscaler_gateway_firmware
0.02EPSS
CVE-2020-8246
Alta 7.5

Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WA…

citrix application_delivery_controller_firmware · citrix gateway · citrix netscaler_gateway · citrix sd-wan_wanop
0.02EPSS
CVE-2019-12044
Alta 7.5

A Buffer Overflow exists in Citrix NetScaler Gateway 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23 and Citrix Application Delivery Controller 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x b…

citrix netscaler_application_delivery_controller_firmware · citrix netscaler_gateway_firmware
0.02EPSS
CVE-2020-8210
Alta 7.5

Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 discloses credentials of a service account.

citrix xenmobile_server
0.02EPSS
CVE-2020-8211
Critica 9.8

Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows SQL Injection.

citrix xenmobile_server
0.02EPSS
CVE-2013-2767
Media 5.4

Unspecified vulnerability in Citrix NetScaler Access Gateway Enterprise Edition (AGEE) before 9.3.62.4 and 10.x through 10.0.74.4, and NetScaler AGEE Common Criteria build before 9.3.53.6, allows remote attackers to bypass intended intranet access restrictions…

citrix netscaler_access_gateway · citrix netscaler_access_gateway_firmware
0.02EPSS
CVE-2023-3467
Alta 8.0

Privilege Escalation to root administrator (nsroot)

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
0.02EPSS