Skip to main content

Vendor archive

citrix CVEs

Beta · best-effort

455 CVEs tagged to vendor citrix75 Critical, 170 High, 195 Medium, 15 Low, 0 Unrated.

CVE-2015-7999

Published Apr 14, 2016

Multiple SQL injection vulnerabilities in the Administration Web UI servlets in Citrix Command Center before 5.1 Build 36.7 and 5.2 before Build 44.11 allow remote authenticated u…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8555

Published Apr 13, 2016

Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2789

Published Apr 7, 2016

Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling Patch 4, and 10.3 before Rolling Patch 1 allows remote atta…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1571

Published Jan 22, 2016

The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2841

Published Apr 3, 2015

Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restrictions via a crafted Content-Type header, as demonstrated by the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2840

Published Apr 3, 2015

Cross-site scripting (XSS) vulnerability in help/rt/large_search.html in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to inject arbitrary web script or HTML v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2839

Published Apr 3, 2015

The Nitro API in Citrix NetScaler before 10.5 build 52.3nc uses an incorrect Content-Type when returning an error message, which allows remote attackers to conduct cross-site scri…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2838

Published Apr 3, 2015

Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to hijack the authentication of administrators fo…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2683

Published Mar 26, 2015

Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 does not properly restrict access to the Advent Java Management Extensions (JMX) Servlet, which allows remote…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-2682

Published Mar 26, 2015

Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via a direct request to conf/securitydbData.xml.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8495

Published Oct 31, 2014

Citrix XenMobile MDX Toolkit before 9.0.4, when used to wrap iOS 8 applications, does not properly encrypt cached application data, which allows context-dependent attackers to obt…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2593

Published Aug 12, 2014

Integer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9.x before 9.3-57.5 and 10.0 be…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4948

Published Jul 22, 2014

Unspecified vulnerability in Citrix XenServer 6.2 Service Pack 1 and earlier allows attackers to cause a denial of service and obtain sensitive information by modifying the guest…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 301-325 of 455 CVEsPage 13 of 19