Vulnerability index

Browse CVEs

331 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Access Essentials HIGH 10.0
CVE-2008-0356EPSS 73%

Buffer overflow in the Independent Management Architecture (IMA) service in Citrix Presentation Server (MetaFrame Presentation Server) 4.5 and earlie…

Fix: after 4.5
Fix from $1,950 2008-01-18
Netscaler MEDIUM 5.0
CVE-2007-6193

The web management interface in Citrix NetScaler 8.0 build 47.8 stores the device's primary IP address in a cookie, which might allow remote attacker…

Mitigation only
Fix from $1,600 2007-11-30
Access Gateway MEDIUM 5.0
CVE-2007-0011

The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL…

Patch available
Fix from $1,600 2007-11-05
Access Gateway HIGH 9.3
CVE-2007-4013

Multiple unspecified vulnerabilities in (1) Net6Helper.DLL (aka Net6Launcher Class) 4.5.2 and earlier, (2) npCtxCAO.dll (aka Citrix Endpoint Analysis…

Fix: after 4.5
Fix from $1,950 2007-07-26
Access Gateway HIGH 7.6
CVE-2007-4017

Cross-site request forgery (CSRF) vulnerability in the web-based administration console in Citrix Access Gateway before firmware 4.5.5 allows remote …

Patch available
Fix from $1,950 2007-07-26
Access Gateway MEDIUM 6.8
CVE-2007-4016

Unspecified vulnerability in the client components in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows …

Fix: after 4.5
Fix from $1,600 2007-07-26
Access Gateway MEDIUM 6.8
CVE-2007-4018

Citrix Access Gateway Advanced Edition before firmware 4.5.5 allows attackers to redirect users to arbitrary web sites and conduct phishing attacks v…

Fix: after 4.5
Fix from $1,600 2007-07-26
Metaframe Presentation Server MEDIUM 5.0
CVE-2007-3625

The Program Neighborhood Agent in Citrix Presentation Server Clients for 32-bit Windows before 10.100 allows remote attackers to cause a denial of se…

Fix: after 10.100
Fix from $1,600 2007-07-09
Access Essentials HIGH 10.0
CVE-2007-2850

The Session Reliability Service (XTE) in Citrix MetaFrame Presentation Server 3.0, Presentation Server 4.0, and Access Essentials 1.0 and 1.5, allows…

Patch available
Fix from $1,950 2007-05-24
Presentation Server Client HIGH 9.3
CVE-2007-1196

Unspecified vulnerability in Citrix Presentation Server Client for Windows before 10.0 allows remote web sites to execute arbitrary code via unspecif…

Fix: after 9.200
Fix from $1,950 2007-03-02
Metaframe HIGH 7.2
CVE-2007-0444EPSS 14%

Stack-based buffer overflow in the print provider library (cpprov.dll) in Citrix Presentation Server 4.0, MetaFrame Presentation Server 3.0, and Meta…

Mitigation only
Fix from $1,950 2007-01-24
Access Gateway MEDIUM 6.5
CVE-2006-6572

Unspecified vulnerability in Citrix Advanced Access Control (AAC) Option 4.0, and Access Gateway 4.2 with Advanced Access Control 4.2, before 2006111…

Patch available
Fix from $1,600 2006-12-15
Access Gateway MEDIUM 6.0
CVE-2006-6573

Unspecified vulnerability in Citrix Access Gateway 4.5 Advanced Edition, and 4.2 with Advanced Access Control (AAC) 4.2, when deployed on the Access …

Patch available
Fix from $1,600 2006-12-15
Presentation Server Client MEDIUM 6.8
CVE-2006-6334EPSS 35%

Heap-based buffer overflow in the SendChannelData function in wfica.ocx in Citrix Presentation Server Client before 9.230 for Windows allows remote m…

Fix: after 9.200
Fix from $1,600 2006-12-08
Metaframe HIGH 7.5
CVE-2006-5821EPSS 5%

Heap-based buffer overflow in the IMA_SECURE_DecryptData1 function in ImaSystem.dll for Citrix MetaFrame XP 1.0 and 2.0, and Presentation Server 3.0 …

Patch available
Fix from $1,950 2006-11-10
Metaframe MEDIUM 5.0
CVE-2006-5861

The Independent Management Architecture (IMA) service (ImaSrv.exe) in Citrix MetaFrame XP 1.0 and 2.0, and Presentation Server 3.0 and 4.0, allows re…

Patch available
Fix from $1,600 2006-11-10
Access Gateway MEDIUM 5.1
CVE-2006-4846

Unspecified vulnerability in Citrix Access Gateway with Advanced Access Control (AAC) 4.2 before 20060914, when AAC is configured to use LDAP authent…

Patch available
Fix from $1,600 2006-09-19
Metaframe MEDIUM 6.5
CVE-2006-3779

Citrix MetaFrame up to XP 1.0 Feature 1, except when running on Windows Server 2003, installs a registry key with an insecure ACL, which allows remot…

Patch available
Fix from $1,600 2006-07-24
Ica Program Neighborhood Client HIGH 7.5
CVE-2005-3652EPSS 16%

Heap-based buffer overflow in Citrix Program Neighborhood client 9.0 and earlier allows remote attackers to execute arbitrary code via a long name va…

Patch available
Fix from $1,950 2005-12-16
Metaframe HIGH 7.5
CVE-2005-3134

Citrix Metaframe Presentation Server 3.0 and 4.0 allows remote attackers to bypass policy restrictions by downloading the launch.ica file and changin…

No fix yet
Fix from $1,950 2005-10-04
Metaframe Client HIGH 7.5
CVE-2004-1078

Stack-based buffer overflow in the client for Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and Citrix MetaFrame Presentation Se…

Patch available
Fix from $1,950 2004-04-26
Metaframe Client MEDIUM 5.0
CVE-2004-1077

Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and MetaFrame Presentation Server client for WinCE before 8.33 allows remote serve…

Patch available
Fix from $1,600 2004-04-26
Nfuse HIGH 7.5
CVE-2002-0504EPSS 8%

Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers…

Fix: after 1.6
Fix from $1,950 2002-08-12
Nfuse MEDIUM 5.0
CVE-2002-0502

Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page.

Mitigation only
Fix from $1,600 2002-08-12
Nfuse MEDIUM 5.0
CVE-2002-0503

Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot…

Patch available
Fix from $1,600 2002-08-12
Nfuse MEDIUM 5.0
CVE-2002-0301

Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_…

Mitigation only
Fix from $1,600 2002-05-31
Ica Client HIGH 7.5
CVE-2001-1192

Citrix Independent Computing Architecture (ICA) Client for Windows 6.1 allows remote malicious web sites to execute arbitrary code via a .ICA file, w…

Patch available
Fix from $1,950 2001-12-13
Metaframe MEDIUM 5.0
CVE-2001-0716

Citrix MetaFrame 1.8 Server with Service Pack 3, and XP Server Service Pack 1 and earlier, allows remote attackers to cause a denial of service (cras…

Patch available
Fix from $1,600 2001-12-06
Metaframe HIGH 7.5
CVE-2001-0908

CITRIX Metaframe 1.8 logs the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allow…

Mitigation only
Fix from $1,950 2001-11-21
Nfuse MEDIUM 5.0
CVE-2001-0760

Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not provide the…

No fix yet
Fix from $1,600 2001-10-18