Skip to main content

Vendor archive

citrix CVEs

Beta · best-effort

455 CVEs tagged to vendor citrix75 Critical, 170 High, 195 Medium, 15 Low, 0 Unrated.

CVE-2019-13608

Published Aug 29, 2019

Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.

CVSS 7.5 · High
Buzz score
25.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2019-12991

Published Jul 16, 2019

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).

CVSS 8.8 · High
evidence mentions
1
Buzz score
36.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2014-3798

Published Jul 11, 2019

The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted Ethernet frame.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12292

Published Jun 24, 2019

Citrix AppDNA before 7 1906.1.0.472 has Incorrect Access Control.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-18571

Published Jun 5, 2019

An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersona…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-7218

Published May 13, 2019

Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline victim's otp physical token or…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7217

Published May 13, 2019

Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on different server responses using the request to check the otp code…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19965

Published Dec 8, 2018

An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-18014

Published Oct 24, 2018

* Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by making requests to private services listening on…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 201-225 of 455 CVEsPage 9 of 19