Vulnerability index

Browse CVEs

331 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xenserver HIGH 8.8
CVE-2017-12134

The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and con…

Patch available
Fix from $1,950 2017-08-24
Xenserver HIGH 8.8
CVE-2017-12135

Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involvin…

Patch available
Fix from $1,950 2017-08-24
Xenserver HIGH 8.8
CVE-2017-12137

arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.

Patch available
Fix from $1,950 2017-08-24
Xenserver HIGH 7.8
CVE-2017-12136

Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corrup…

Patch available
Fix from $1,950 2017-08-24
Xenserver CRITICAL 9.8
CVE-2015-7705EPSS 12%

The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of …

Fix: 4.2.8 / 4.3.77+
Fix from $2,300 2017-08-07
Netscaler Application Delivery Controller MEDIUM 5.9
CVE-2015-3642

The TLS and DTLS processing functionality in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices with firmware 9.x b…

Mitigation only
Fix from $1,600 2017-08-02
Netscaler Sd Wan CRITICAL 9.8
CVE-2017-6316 KEVEPSS 73%

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. O…

Fix: after 9.1.2.26.561201
Fix from $2,300 2017-07-20
Xenmobile Server HIGH 7.5
CVE-2017-9231

XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via …

Mitigation only
Fix from $1,950 2017-06-16
Xenmobile Server MEDIUM 5.3
CVE-2016-6877

Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving the HTTP Host head…

Fix: after 10.3.6.310
Fix from $1,600 2017-05-05
Netscaler Gateway Firmware HIGH 8.8
CVE-2017-7219

A heap overflow vulnerability in Citrix NetScaler Gateway versions 10.1 before 135.8/135.12, 10.5 before 65.11, 11.0 before 70.12, and 11.1 before 52…

Patch available
Fix from $1,950 2017-04-13
Xenserver HIGH 7.5
CVE-2016-9637

The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS adminis…

Mitigation only
Fix from $1,950 2017-02-17
Netscaler Application Delivery Controller Firmware MEDIUM 5.9
CVE-2017-5933

Citrix NetScaler ADC and NetScaler Gateway 10.5 before Build 65.11, 11.0 before Build 69.12/69.123, and 11.1 before Build 51.21 randomly generates GC…

Fix: after 11.1.51.21
Fix from $1,600 2017-02-08
Xenserver MEDIUM 6.5
CVE-2017-5572

An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated read-only administrator can corrupt the host datab…

Mitigation only
Fix from $1,600 2017-01-30
Xenserver MEDIUM 6.0
CVE-2016-10024

Xen through 4.8.x allows local x86 PV guest OS kernel administrators to cause a denial of service (host hang or crash) by modifying the instruction s…

Fix: after 4.8.0
Fix from $1,600 2017-01-26
Xenserver MEDIUM 5.5
CVE-2016-10025

VMFUNC emulation in Xen 4.6.x through 4.8.x on x86 systems using AMD virtualization extensions (aka SVM) allows local HVM guest OS users to cause a d…

Patch available
Fix from $1,600 2017-01-26
Xenserver HIGH 8.8
CVE-2016-9383

Xen, when running on a 64-bit hypervisor, allows local x86 guest OS users to modify arbitrary memory and consequently obtain sensitive information, c…

Patch available
Fix from $1,950 2017-01-23
Xenserver HIGH 7.9
CVE-2016-9379

The pygrub boot loader emulator in Xen, when S-expression output format is requested, allows local pygrub-using guest OS administrators to read or de…

Patch available
Fix from $1,950 2017-01-23
Xenserver HIGH 7.8
CVE-2016-9382

Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to gain privileges or cause a deni…

Patch available
Fix from $1,950 2017-01-23
Xenserver HIGH 7.8
CVE-2016-9386

The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory, which might allow local HVM guest users to gain …

Patch available
Fix from $1,950 2017-01-23
Xenserver HIGH 7.5
CVE-2016-9380

The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest OS administrators to read or d…

Patch available
Fix from $1,950 2017-01-23
Xenserver HIGH 7.5
CVE-2016-9381

Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double…

Fix: after 2.7.1
Fix from $1,950 2017-01-23
Xenserver MEDIUM 6.0
CVE-2016-9385

The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of servic…

Patch available
Fix from $1,600 2017-01-23
Provisioning Services CRITICAL 9.8
CVE-2016-9679

Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code by overwriting a function pointer.

Mitigation only
Fix from $2,300 2017-01-18
Provisioning Services HIGH 7.5
CVE-2016-9680

Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive information from kernel memory via unspecified vectors.

Mitigation only
Fix from $1,950 2017-01-18
Provisioning Services CRITICAL 9.8
CVE-2016-9676

Buffer overflow in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.

Mitigation only
Fix from $2,300 2017-01-18
Provisioning Services CRITICAL 9.8
CVE-2016-9678

Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.

Mitigation only
Fix from $2,300 2017-01-18
Provisioning Services MEDIUM 5.3
CVE-2016-9677

Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified vectors.

Mitigation only
Fix from $1,600 2017-01-18
Receiver Desktop MEDIUM 6.8
CVE-2016-9111

Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication requirement by leveraging phys…

No fix yet
Fix from $1,600 2016-11-07
Netscaler Application Delivery Controller Firmware HIGH 8.8
CVE-2016-9028

Unauthorized redirect vulnerability in Citrix NetScaler ADC before 10.1 135.8, 10.5 61.11, 11.0 65.31/65.35F and 11.1 47.14 allows a remote attacker …

Fix: after 10.1
Fix from $1,950 2016-10-28
License Server HIGH 7.5
CVE-2016-6273

The lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) before 2015 SP5 and 2016 before R1 SP1, as used by Citrix License Serve…

Fix: after 11.14.0.0
Fix from $1,950 2016-10-07