Skip to main content

Vendor archive

citrix CVEs

Beta · best-effort

455 CVEs tagged to vendor citrix75 Critical, 170 High, 195 Medium, 15 Low, 0 Unrated.

CVE-2016-9385

Published Jan 23, 2017

The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of service (host crash) by leveraging l…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9383

Published Jan 23, 2017

Xen, when running on a 64-bit hypervisor, allows local x86 guest OS users to modify arbitrary memory and consequently obtain sensitive information, cause a denial of service (host…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9382

Published Jan 23, 2017

Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to gain privileges or cause a denial of service (guest OS crash)…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9381

Published Jan 23, 2017

Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double fetch" vulnerability.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9380

Published Jan 23, 2017

The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the h…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9379

Published Jan 23, 2017

The pygrub boot loader emulator in Xen, when S-expression output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the ho…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9680

Published Jan 18, 2017

Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive information from kernel memory via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9678

Published Jan 18, 2017

Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-9677

Published Jan 18, 2017

Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified vectors.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9676

Published Jan 18, 2017

Buffer overflow in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-9111

Published Nov 7, 2016

Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication requirement by leveraging physical access to a VDI for tempo…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6273

Published Oct 7, 2016

The lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) before 2015 SP5 and 2016 before R1 SP1, as used by Citrix License Server for Windows before 11.14.0.1…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6276

Published Sep 26, 2016

Citrix Linux Virtual Delivery Agent (aka VDA, formerly Linux Virtual Desktop) before 1.4.0 allows local users to gain root privileges via unspecified vectors.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6493

Published Aug 19, 2016

Citrix XenApp 6.x before 6.5 HRP07 and 7.x before 7.9 and Citrix XenDesktop before 7.9 might allow attackers to weaken an unspecified security mitigation via vectors related to me…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6259

Published Aug 2, 2016

Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernel…

CVSS 6.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-6258

Published Aug 2, 2016

The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pag…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-5433

Published Jun 17, 2016

Citrix iOS Receiver before 7.0 allows attackers to cause TLS certificates to be incorrectly validated via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5302

Published Jun 13, 2016

Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-4810

Published Jun 1, 2016

Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the Xen…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3712

Published May 11, 2016

Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mod…

CVSS 5.5 · Medium
Showing 276-300 of 455 CVEsPage 12 of 19