Vulnerability index

Browse CVEs

331 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Linux Virtual Delivery Agent HIGH 7.8
CVE-2016-6276

Citrix Linux Virtual Delivery Agent (aka VDA, formerly Linux Virtual Desktop) before 1.4.0 allows local users to gain root privileges via unspecified…

Fix: after 1.3
Fix from $1,950 2016-09-26
Xenapp CRITICAL 9.8
CVE-2016-6493

Citrix XenApp 6.x before 6.5 HRP07 and 7.x before 7.9 and Citrix XenDesktop before 7.9 might allow attackers to weaken an unspecified security mitiga…

Fix: after 7.8
Fix from $2,300 2016-08-19
Xenserver MEDIUM 6.2
CVE-2016-6259

Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows l…

Patch available
Fix from $1,600 2016-08-02
Xenserver HIGH 8.8
CVE-2016-6258

The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveragi…

Patch available
Fix from $1,950 2016-08-02
Ios Receiver MEDIUM 6.1
CVE-2016-5433

Citrix iOS Receiver before 7.0 allows attackers to cause TLS certificates to be incorrectly validated via unspecified vectors.

Fix: after 6.1.5
Fix from $1,600 2016-06-17
Xenserver CRITICAL 9.8
CVE-2016-5302

Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the managem…

Fix: after 7.0
Fix from $2,300 2016-06-13
Netscaler Gateway 11.0 Firmware MEDIUM 6.1
CVE-2016-4945

Cross-site scripting (XSS) vulnerability in vpn/js/gateway_login_form_view.js in Citrix NetScaler Gateway 11.0 before Build 66.11 allows remote attac…

Fix: after 65.35
Fix from $1,600 2016-06-01
Xenapp HIGH 7.5
CVE-2016-4810

Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set …

Mitigation only
Fix from $1,950 2016-06-01
Command Center HIGH 8.1
CVE-2015-7999

Multiple SQL injection vulnerabilities in the Administration Web UI servlets in Citrix Command Center before 5.1 Build 36.7 and 5.2 before Build 44.1…

Mitigation only
Fix from $1,950 2016-04-14
Xenserver HIGH 8.6
CVE-2015-8555

Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended…

Patch available
Fix from $1,950 2016-04-13
Xenmobile Server MEDIUM 6.1
CVE-2016-2789

Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling Patch 4, and 10.3 before Roll…

Patch available
Fix from $1,600 2016-04-07
Netscaler MEDIUM 6.1
CVE-2016-2072

The Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 b…

Mitigation only
Fix from $1,600 2016-02-17
Netscaler CRITICAL 9.8
CVE-2016-2071

Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, and 10.5.e b…

Mitigation only
Fix from $2,300 2016-02-17
Xenserver MEDIUM 6.3
CVE-2016-1571

The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled,…

Fix: after 6.5
Fix from $1,600 2016-01-22
Netscaler Service Delivery Appliance Service Vm MEDIUM 5.0
CVE-2015-7998

The administration UI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.1…

Patch available
Fix from $1,600 2015-11-17
Netscaler Application Delivery Controller Firmware MEDIUM 5.0
CVE-2015-7996

The Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 1…

Patch available
Fix from $1,600 2015-11-17
Netscaler Application Delivery Controller Firmware HIGH 10.0
CVE-2015-5538

Multiple unspecified vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 be…

Mitigation only
Fix from $1,950 2015-09-17
Netscaler Application Delivery Controller Firmware HIGH 9.0
CVE-2015-5080

The Management Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before 10.1.132.8, 10.5 before Build 56…

Mitigation only
Fix from $1,950 2015-07-16
Netscaler Application Delivery Controller Firmware HIGH 7.8
CVE-2015-2829

Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.5 Build 53.9 through 55.8 and 10.5.e Build 53-9010.e allow rem…

Patch available
Fix from $1,950 2015-05-12
Netscaler MEDIUM 5.0
CVE-2015-2841EPSS 6%

Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restrictions via a crafted Content-Type …

No fix yet
Fix from $1,600 2015-04-03
Netscaler MEDIUM 6.8
CVE-2015-2838

Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to hijack the authe…

No fix yet
Fix from $1,600 2015-04-03
Command Center HIGH 7.5
CVE-2015-2683EPSS 5%

Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 does not properly restrict access to the Advent Java Management Extensions (JMX…

No fix yet
Fix from $1,950 2015-03-26
Command Center MEDIUM 5.0
CVE-2015-2682EPSS 11%

Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via a direct request to conf/secu…

No fix yet
Fix from $1,600 2015-03-26
Xenmobile MEDIUM 5.0
CVE-2014-8495

Citrix XenMobile MDX Toolkit before 9.0.4, when used to wrap iOS 8 applications, does not properly encrypt cached application data, which allows cont…

Fix: after 9.0.3
Fix from $1,600 2014-10-31
Netscaler Application Delivery Controller Firmware HIGH 7.5
CVE-2014-7140EPSS 16%

Unspecified vulnerability in the management interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.x before 10.…

Mitigation only
Fix from $1,950 2014-10-21
Access Gateway Plug In MEDIUM 6.8
CVE-2011-2593

Integer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9…

Fix: after 9.3
Fix from $1,600 2014-08-12
Xenserver HIGH 10.0
CVE-2014-4947EPSS 5%

Buffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earlier has unspecified impact and attack vectors.

Mitigation only
Fix from $1,950 2014-07-22
Xenserver MEDIUM 6.4
CVE-2014-4948

Unspecified vulnerability in Citrix XenServer 6.2 Service Pack 1 and earlier allows attackers to cause a denial of service and obtain sensitive infor…

Mitigation only
Fix from $1,600 2014-07-22
Netscaler Access Gateway Firmware MEDIUM 5.0
CVE-2014-4347

Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) before 9.3-62.4 and 10.x be…

No fix yet
Fix from $1,600 2014-07-16
Access Gateway Plug In HIGH 9.3
CVE-2011-2592EPSS 15%

Heap-based buffer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for…

Mitigation only
Fix from $1,950 2014-06-18