Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2016-6276
Citrix Linux Virtual Delivery Agent (aka VDA, formerly Linux Virtual Desktop) before 1.4.0 allows local users to gain root privileges via unspecified…
Linux Virtual Delivery Agent
after 1.3
CRITICAL 9.8
CVE-2016-6493
Citrix XenApp 6.x before 6.5 HRP07 and 7.x before 7.9 and Citrix XenDesktop before 7.9 might allow attackers to weaken an unspecified security mitiga…
Xenapp
after 7.8
MEDIUM 6.2
CVE-2016-6259
Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows l…
Xenserver
Patch available
HIGH 8.8
CVE-2016-6258
The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveragi…
Xenserver
Patch available
MEDIUM 6.1
CVE-2016-5433
Citrix iOS Receiver before 7.0 allows attackers to cause TLS certificates to be incorrectly validated via unspecified vectors.
Ios Receiver
after 6.1.5
CRITICAL 9.8
CVE-2016-5302
Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the managem…
Xenserver
after 7.0
MEDIUM 6.1
CVE-2016-4945
Cross-site scripting (XSS) vulnerability in vpn/js/gateway_login_form_view.js in Citrix NetScaler Gateway 11.0 before Build 66.11 allows remote attac…
Netscaler Gateway 11.0 Firmware
after 65.35
HIGH 7.5
CVE-2016-4810
Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set …
Xenapp
Mitigation only
HIGH 8.1
CVE-2015-7999
Multiple SQL injection vulnerabilities in the Administration Web UI servlets in Citrix Command Center before 5.1 Build 36.7 and 5.2 before Build 44.1…
Command Center
Mitigation only
HIGH 8.6
CVE-2015-8555
Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended…
Xenserver
Patch available
MEDIUM 6.1
CVE-2016-2789
Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling Patch 4, and 10.3 before Roll…
Xenmobile Server
Patch available
MEDIUM 6.1
CVE-2016-2072
The Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 b…
Netscaler
Mitigation only
CRITICAL 9.8
CVE-2016-2071
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, and 10.5.e b…
Netscaler
Mitigation only
MEDIUM 6.3
CVE-2016-1571
The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled,…
Xenserver
after 6.5
MEDIUM 5.0
CVE-2015-7998
The administration UI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.1…
Netscaler Service Delivery Appliance Service Vm
Patch available
MEDIUM 5.0
CVE-2015-7996
The Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 1…
Netscaler Application Delivery Controller Firmware
Patch available
HIGH 10.0
CVE-2015-5538
Multiple unspecified vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 be…
Netscaler Application Delivery Controller Firmware
Mitigation only
HIGH 9.0
CVE-2015-5080
The Management Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before 10.1.132.8, 10.5 before Build 56…
Netscaler Application Delivery Controller Firmware
Mitigation only
HIGH 7.8
CVE-2015-2829
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.5 Build 53.9 through 55.8 and 10.5.e Build 53-9010.e allow rem…
Netscaler Application Delivery Controller Firmware
Patch available
MEDIUM 5.0
CVE-2015-2841EPSS 6%
Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restrictions via a crafted Content-Type …
Netscaler
No fix yet
MEDIUM 6.8
CVE-2015-2838
Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to hijack the authe…
Netscaler
No fix yet
HIGH 7.5
CVE-2015-2683EPSS 5%
Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 does not properly restrict access to the Advent Java Management Extensions (JMX…
Command Center
No fix yet
MEDIUM 5.0
CVE-2015-2682EPSS 11%
Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via a direct request to conf/secu…
Command Center
No fix yet
MEDIUM 5.0
CVE-2014-8495
Citrix XenMobile MDX Toolkit before 9.0.4, when used to wrap iOS 8 applications, does not properly encrypt cached application data, which allows cont…
Xenmobile
after 9.0.3
HIGH 7.5
CVE-2014-7140EPSS 16%
Unspecified vulnerability in the management interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.x before 10.…
Netscaler Application Delivery Controller Firmware
Mitigation only
MEDIUM 6.8
CVE-2011-2593
Integer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9…
Access Gateway Plug In
after 9.3
HIGH 10.0
CVE-2014-4947EPSS 5%
Buffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earlier has unspecified impact and attack vectors.
Xenserver
Mitigation only
MEDIUM 6.4
CVE-2014-4948
Unspecified vulnerability in Citrix XenServer 6.2 Service Pack 1 and earlier allows attackers to cause a denial of service and obtain sensitive infor…
Xenserver
Mitigation only
MEDIUM 5.0
CVE-2014-4347
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) before 9.3-62.4 and 10.x be…
Netscaler Access Gateway Firmware
No fix yet
HIGH 9.3
CVE-2011-2592EPSS 15%
Heap-based buffer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for…
Access Gateway Plug In
Mitigation only