Skip to main content

Vendor archive

citrix CVEs

Beta · best-effort

455 CVEs tagged to vendor citrix75 Critical, 170 High, 195 Medium, 15 Low, 0 Unrated.

CVE-2007-2850

Published May 24, 2007

The Session Reliability Service (XTE) in Citrix MetaFrame Presentation Server 3.0, Presentation Server 4.0, and Access Essentials 1.0 and 1.5, allows remote attackers to bypass ne…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-1196

Published Mar 2, 2007

Unspecified vulnerability in Citrix Presentation Server Client for Windows before 10.0 allows remote web sites to execute arbitrary code via unspecified vectors, related to the im…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6572

Published Dec 15, 2006

Unspecified vulnerability in Citrix Advanced Access Control (AAC) Option 4.0, and Access Gateway 4.2 with Advanced Access Control 4.2, before 20061114, when the Browser-Only acces…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6573

Published Dec 15, 2006

Unspecified vulnerability in Citrix Access Gateway 4.5 Advanced Edition, and 4.2 with Advanced Access Control (AAC) 4.2, when deployed on the Access Gateway appliance 4.2 through…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6334

Published Dec 8, 2006

Heap-based buffer overflow in the SendChannelData function in wfica.ocx in Citrix Presentation Server Client before 9.230 for Windows allows remote malicious web sites to execute…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4846

Published Sep 19, 2006

Unspecified vulnerability in Citrix Access Gateway with Advanced Access Control (AAC) 4.2 before 20060914, when AAC is configured to use LDAP authentication, allows remote attacke…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4412

Published Dec 20, 2005

Citrix Program Neighborhood client before 9.150 caches the user password in plaintext in the GUI while asterisks are used to visually obfuscate the password, which allows attacker…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-3652

Published Dec 16, 2005

Heap-based buffer overflow in Citrix Program Neighborhood client 9.0 and earlier allows remote attackers to execute arbitrary code via a long name value in an Application Set resp…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3134

Published Oct 4, 2005

Citrix Metaframe Presentation Server 3.0 and 4.0 allows remote attackers to bypass policy restrictions by downloading the launch.ica file and changing the client device name (Clie…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0821

Published May 2, 2005

Unknown vulnerability in Citrix MetaFrame Conferencing Manager 3.0 allows conference members to bypass organizer restrictions to control the keyboard and mouse.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0822

Published May 2, 2005

Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary pas…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1902

Published Dec 31, 2004

The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wi…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-1157

Published Dec 31, 2003

Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web script or HTML via the NFuse_Message parame…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0502

Published Aug 12, 2002

Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0503

Published Aug 12, 2002

Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parame…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0504

Published Aug 12, 2002

Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other cl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0301

Published May 31, 2002

Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parame…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 426-450 of 455 CVEsPage 18 of 19