← Back

Citrix

citrix

393 CVEs • 153 products

Products (153)

Click to collapse
Toggle
Xenserver
xenserver
Gateway
gateway
Sd Wan
sd-wan
Workspace
workspace
Metaframe
metaframe
Netscaler
netscaler
Sd Wan Wanop
sd-wan_wanop
Xen
xen
Xenapp
xenapp
Xendesktop
xendesktop
Nfuse
nfuse
Web Interface
web_interface
Xencenterweb
xencenterweb
Cloudplatform
cloudplatform
Vdi In A Box
vdi-in-a-box
Netscaler Sdx
netscaler_sdx
Sharefile
sharefile
Receiver
receiver
Workspace App
workspace_app
Secure Mail
secure_mail
Winframe
winframe
Ica Client
ica_client
Xp
xp
Secure Gateway
secure_gateway
Licensing
licensing
Cloudstack
cloudstack
Xenclient Xt
xenclient_xt
Gotomeeting
gotomeeting

CVEs (393)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
17Apple
AristaCanonical+14 more
74Arx Firmware
BashBig Ip Access Policy Manager+71 more
Apr 22, 2026
Sep 25, 2014
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown oth...Show more
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.Show less
17Apple
AristaCanonical+14 more
74Arx Firmware
BashBig Ip Access Policy Manager+71 more
Apr 22, 2026
Sep 24, 2014
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vec...Show more
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.Show less
1Citrix
1Access Gateway Plug In
May 6, 2026
Aug 12, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9.x before 9.3-57.5 and 10.0 before 10.0-69.4 allows remote attackers to...Show more
Integer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9.x before 9.3-57.5 and 10.0 before 10.0-69.4 allows remote attackers to execute arbitrary code via a crafted Content-Length HTTP header, which triggers a heap-based buffer overflow.Show less
1Citrix
1Xenserver
May 6, 2026
Jul 22, 2014
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Unspecified vulnerability in Citrix XenServer 6.2 Service Pack 1 and earlier allows attackers to cause a denial of service and obtain sensitive information by modifying the guest virtual hard disk (VHD).
1Citrix
1Xenserver
May 6, 2026
Jul 22, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earlier has unspecified impact and attack vectors.
1Citrix
4Netscaler Access Gateway
Netscaler Access Gateway FirmwareNetscaler Application Delivery Controller+1 more
May 6, 2026
Jul 16, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) before 9.3-62.4 and 10.x before 10.1-126.12 allows attackers to obtain sensitive information via v...Show more
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) before 9.3-62.4 and 10.x before 10.1-126.12 allows attackers to obtain sensitive information via vectors related to a cookie.Show less
1Citrix
4Netscaler Access Gateway
Netscaler Access Gateway FirmwareNetscaler Application Delivery Controller+1 more
May 6, 2026
Jul 16, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in administration user interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) 10.1 before 10.1-126....Show more
Cross-site scripting (XSS) vulnerability in administration user interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) 10.1 before 10.1-126.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.Show less
1Citrix
1Xendesktop
May 6, 2026
Jul 11, 2014
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user's desktop via unspecified vectors.
1Citrix
1Access Gateway Plug In
May 6, 2026
Jun 18, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9.x before 9.3-57.5 and 10.0 before 10.0-69.4 allows remote at...Show more
Heap-based buffer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9.x before 9.3-57.5 and 10.0 before 10.0-69.4 allows remote attackers to execute arbitrary code via a long CSEC HTTP response header.Show less
1Citrix
1Vdi In A Box
May 6, 2026
May 30, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in Citrix VDI-In-A-Box 5.3.x before 5.3.8 and 5.4.x before 5.4.4 allows remote attackers to bypass authentication via unspecified vectors, related to a Java servlet.
2Apache
Citrix
2Cloudplatform
Cloudstack
May 6, 2026
May 23, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C uses a hash of a predictable sequence, which makes it easier for remote attackers to guess the console...Show more
Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C uses a hash of a predictable sequence, which makes it easier for remote attackers to guess the console access URL via a brute force attack.Show less
1Citrix
1Cloudplatform
May 6, 2026
May 23, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C does not properly restrict access to VNC ports on the management network, which allows remote attackers to have unspecified impact via unknown...Show more
Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C does not properly restrict access to VNC ports on the management network, which allows remote attackers to have unspecified impact via unknown vectors.Show less
2Apache
Citrix
2Cloudplatform
Cloudstack
May 6, 2026
May 23, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypass the console proxy authentication by leveraging knowledge of the sour...Show more
Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypass the console proxy authentication by leveraging knowledge of the source code.Show less
1Citrix
2Netscaler Access Gateway
Netscaler Access Gateway Firmware
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Citrix NetScaler Gateway (formerly Citrix Access Gateway Enterprise Edition) 9.x before 9.3.66.5 and 10.x before 10.1.123.9 allows remote attackers to inject arbitrary web scri...Show more
Cross-site scripting (XSS) vulnerability in Citrix NetScaler Gateway (formerly Citrix Access Gateway Enterprise Edition) 9.x before 9.3.66.5 and 10.x before 10.1.123.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.Show less
1Citrix
4Netscaler Access Gateway
Netscaler Access Gateway FirmwareNetscaler Application Delivery Controller+1 more
May 6, 2026
May 1, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in the management GUI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unspecified impact and vectors, related to c...Show more
Unspecified vulnerability in the management GUI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unspecified impact and vectors, related to certificate validation.Show less
1Citrix
4Netscaler Access Gateway
Netscaler Access Gateway FirmwareNetscaler Application Delivery Controller+1 more
May 6, 2026
May 1, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in the Diffie-Hellman key agreement implementation in the management GUI Java applet in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x befo...Show more
Unspecified vulnerability in the Diffie-Hellman key agreement implementation in the management GUI Java applet in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unknown impact and vectors.Show less
1Citrix
1Vdi In A Box
May 6, 2026
Apr 15, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
Citrix VDI-in-a-Box 5.3.x before 5.3.6 and 5.4.x before 5.4.3 allows local users to obtain administrator credentials by reading the log.
1Citrix
1Netscaler Application Delivery Controller Firmware
May 6, 2026
Mar 11, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the user interface in the AAA TM vServer in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allo...Show more
Cross-site scripting (XSS) vulnerability in the user interface in the AAA TM vServer in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.Show less
1Citrix
1Netscaler Application Delivery Controller Firmware
May 6, 2026
Mar 11, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to conduct an LDAP injection attack via vectors related to SSH and W...Show more
Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to conduct an LDAP injection attack via vectors related to SSH and Web management usernames.Show less
1Citrix
1Netscaler Application Delivery Controller Firmware
May 6, 2026
Mar 11, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to hijack the aut...Show more
Cross-site request forgery (CSRF) vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.Show less