Skip to main content

Vendor archive

citrix CVEs

Beta · best-effort

455 CVEs tagged to vendor citrix75 Critical, 170 High, 195 Medium, 15 Low, 0 Unrated.

CVE-2008-5716

Published Dec 24, 2008

xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service a…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4405

Published Oct 3, 2008

xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM's write access within this tree, whi…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3253

Published Jul 22, 2008

Cross-site scripting (XSS) vulnerability in the XenAPI HTTP interfaces in Citrix XenServer Express, Standard, and Enterprise Edition 4.1.0; Citrix XenServer Dell Edition (Express…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2528

Published Jun 3, 2008

Unspecified vulnerability in Citrix Access Gateway Standard Edition 4.5.7 and earlier and Advanced Edition 4.5 HF2 and earlier allows attackers to bypass authentication and gain "…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6477

Published Dec 20, 2007

Cross-site scripting (XSS) vulnerability in the on-line help feature in Citrix Web Interface 2.0 and earlier, and NFuse, allows remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6192

Published Nov 30, 2007

The web management interface in Citrix NetScaler 8.0 build 47.8 uses weak encryption (XOR of unpadded data) to store credentials within a cookie, which makes it easier for remote…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6193

Published Nov 30, 2007

The web management interface in Citrix NetScaler 8.0 build 47.8 stores the device's primary IP address in a cookie, which might allow remote attackers to obtain sensitive network…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6037

Published Nov 20, 2007

Cross-site scripting (XSS) vulnerability in ws/generic_api_call.pl in Citrix NetScaler 8.0 build 47.8 allows remote attackers to inject arbitrary web script or HTML via the standa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0011

Published Nov 5, 2007

The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-depende…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4016

Published Jul 26, 2007

Unspecified vulnerability in the client components in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows attackers to execute arbitrary…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4017

Published Jul 26, 2007

Cross-site request forgery (CSRF) vulnerability in the web-based administration console in Citrix Access Gateway before firmware 4.5.5 allows remote attackers to perform certain c…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4018

Published Jul 26, 2007

Citrix Access Gateway Advanced Edition before firmware 4.5.5 allows attackers to redirect users to arbitrary web sites and conduct phishing attacks via unknown vectors.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3679

Published Jul 25, 2007

The Citrix EPA ActiveX control (aka the "endpoint checking control" or CCAOControl Object) before 4.5.0.0 in npCtxCAO.dll in Citrix Access Gateway Standard Edition before 4.5.5 an…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3625

Published Jul 9, 2007

The Program Neighborhood Agent in Citrix Presentation Server Clients for 32-bit Windows before 10.100 allows remote attackers to cause a denial of service (agent exit) via a certa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 401-425 of 455 CVEsPage 17 of 19