Vulnerability index

Browse CVEs

331 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xenserver MEDIUM 5.6
CVE-2012-3498

PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host cra…

Fix: after 6.0.2
Fix from $1,600 2012-11-23
Provisioning Services HIGH 7.5
CVE-2012-4068

Heap-based buffer overflow in the SoapServer service in Citrix Provisioning Services 5.0, 5.1, 5.6, 5.6 SP1, 6.0, and 6.1 allows remote attackers to …

Patch available
Fix from $1,950 2012-07-26
Xen HIGH 7.4
CVE-2011-1898

Xen 4.1 before 4.1.1 and 4.0 before 4.0.2, when using PCI passthrough on Intel VT-d chipsets that do not have interrupt remapping, allows guest OS us…

Patch available
Fix from $1,950 2011-08-12
Xen MEDIUM 6.9
CVE-2011-1583

Multiple integer overflows in tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allow local users to cause a denial of service and pos…

Patch available
Fix from $1,600 2011-08-12
Access Gateway HIGH 9.3
CVE-2011-2882EPSS 56%

Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.…

Mitigation only
Fix from $1,950 2011-07-21
Access Gateway HIGH 9.3
CVE-2011-2883

The NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 befo…

Mitigation only
Fix from $1,950 2011-07-21
Licensing Administration Console MEDIUM 6.8
CVE-2011-1101

Multiple unspecified vulnerabilities in a third-party component of the Citrix Licensing Administration Console 11.6, formerly License Management Cons…

No fix yet
Fix from $1,600 2011-02-25
Xen MEDIUM 6.1
CVE-2010-4255

The fixup_page_fault function in arch/x86/traps.c in Xen 4.0.1 and earlier on 64-bit platforms, when paravirtualization is enabled, does not verify t…

Fix: after 4.0.1
Fix from $1,600 2011-01-25
Xen MEDIUM 5.5
CVE-2010-4238

The vbd_create function in Xen 3.1.2, when the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 is used, allows guest OS users to cause a den…

No fix yet
Fix from $1,600 2011-01-22
Access Gateway HIGH 9.3
CVE-2010-4566EPSS 28%

The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authen…

Fix: after 9.2-49.8
Fix from $1,950 2011-01-14
Xen MEDIUM 5.5
CVE-2010-4247

The do_block_io_op function in (1) drivers/xen/blkback/blkback.c and (2) drivers/xen/blktap/blktap.c in Xen before 3.4.0 for the Linux kernel 2.6.18,…

Fix: after 3.3.2
Fix from $1,600 2011-01-11
Ica Client For Linux HIGH 9.3
CVE-2010-2990

Citrix Online Plug-in for Windows for XenApp & XenDesktop before 11.2, Citrix Online Plug-in for Mac for XenApp & XenDesktop before 11.0, Citrix ICA …

Fix: after 11.1
Fix from $1,950 2010-08-11
Online Plug In For Windows For Xenapp \& Xendesktop HIGH 9.3
CVE-2010-2991EPSS 7%

The IICAClient interface in the ICAClient library in the ICA Client ActiveX Object (aka ICO) component in Citrix Online Plug-in for Windows for XenAp…

Fix: after 12.0
Fix from $1,950 2010-08-11
Online Plug In For Mac MEDIUM 5.8
CVE-2009-3936

Unspecified vulnerability in Citrix Online Plug-in for Windows 11.0.x before 11.0.150 and 11.x before 11.2, Online Plug-in for Mac before 11.0, Recei…

Fix: after 11.2
Fix from $1,600 2009-11-13
Xencenterweb HIGH 8.8
CVE-2009-3759

Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers…

No fix yet
Fix from $1,950 2009-10-22
Xencenterweb HIGH 7.5
CVE-2009-3758

SQL injection vulnerability in login.php in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to execute arbit…

No fix yet
Fix from $1,950 2009-10-22
Xencenterweb HIGH 7.5
CVE-2009-3760

Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote a…

No fix yet
Fix from $1,950 2009-10-22
Licensing HIGH 10.0
CVE-2009-2452

Multiple unspecified vulnerabilities in Citrix Licensing 11.5 have unknown impact and attack vectors, related to "underlying components of the Licens…

Patch available
Fix from $1,950 2009-07-14
Presentation Server HIGH 7.5
CVE-2009-2453

Citrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Adva…

Patch available
Fix from $1,950 2009-07-14
Netscaler Access Gateway Firmware MEDIUM 6.5
CVE-2009-2213

The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1,…

Fix: after 8.1
Fix from $1,600 2009-06-25
Secure Gateway MEDIUM 5.0
CVE-2009-2214

The Secure Gateway service in Citrix Secure Gateway 3.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an uns…

Fix: after 3.1
Fix from $1,600 2009-06-25
Broadcast Server HIGH 7.5
CVE-2008-5882

SQL injection vulnerability in login.asp in Citrix Application Gateway - Broadcast Server (BCS) before 6.1, as used by Avaya AG250 - Broadcast Server…

Fix: after 6.0
Fix from $1,950 2009-01-09
Xen HIGH 7.2
CVE-2008-5716

xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users …

Mitigation only
Fix from $1,950 2008-12-24
Deterministic Network Enhancer HIGH 7.2
CVE-2008-5121

dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, …

No fix yet
Fix from $1,950 2008-11-18
Access Essentials MEDIUM 6.8
CVE-2008-4676

Unspecified vulnerability in Citrix XenApp (formerly Presentation Server) 4.5 Feature Pack 1 and earlier, Presentation Server 4.0, and Access Essenti…

Fix: after 4.5
Fix from $1,600 2008-10-22
Xen HIGH 7.2
CVE-2008-4405

xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM's writ…

No fix yet
Fix from $1,950 2008-10-03
Metaframe Presentation Server HIGH 7.2
CVE-2008-3485

Untrusted search path vulnerability in Citrix MetaFrame Presentation Server allows local users to gain privileges via a malicious icabar.exe placed i…

Fix: after 3.0
Fix from $1,950 2008-08-06
Access Gateway HIGH 10.0
CVE-2008-2528

Unspecified vulnerability in Citrix Access Gateway Standard Edition 4.5.7 and earlier and Advanced Edition 4.5 HF2 and earlier allows attackers to by…

Fix: after 4.5.7
Fix from $1,950 2008-06-03
Access Essentials MEDIUM 6.5
CVE-2008-2300

Unspecified vulnerability in Citrix Presentation Server 4.5 and earlier, Citrix Access Essentials 2.0 and earlier, and Citrix Desktop Server 1.0 allo…

Fix: after 4.5
Fix from $1,600 2008-05-18
Presentation Server MEDIUM 5.0
CVE-2008-2299

Unspecified vulnerability in SecureICA and ICA Basic encryption of Citrix Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, and…

Fix: after 4.5
Fix from $1,600 2008-05-18