← Back

Citrix

citrix

393 CVEs • 153 products

Products (153)

Click to collapse
Toggle
Xenserver
xenserver
Gateway
gateway
Sd Wan
sd-wan
Workspace
workspace
Metaframe
metaframe
Netscaler
netscaler
Sd Wan Wanop
sd-wan_wanop
Xen
xen
Xenapp
xenapp
Xendesktop
xendesktop
Nfuse
nfuse
Web Interface
web_interface
Xencenterweb
xencenterweb
Cloudplatform
cloudplatform
Vdi In A Box
vdi-in-a-box
Netscaler Sdx
netscaler_sdx
Sharefile
sharefile
Receiver
receiver
Workspace App
workspace_app
Secure Mail
secure_mail
Winframe
winframe
Ica Client
ica_client
Xp
xp
Secure Gateway
secure_gateway
Licensing
licensing
Cloudstack
cloudstack
Xenclient Xt
xenclient_xt
Gotomeeting
gotomeeting

CVEs (393)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Citrix
1Access Gateway
Apr 29, 2026
Jan 14, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions bef...Show more
The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers to execute arbitrary commands via shell metacharacters in the password field.Show less
1Citrix
1Xen
Apr 29, 2026
Jan 11, 2011
N/A· v4
N/A· v3
5.5 MEDIUM· v2
The do_block_io_op function in (1) drivers/xen/blkback/blkback.c and (2) drivers/xen/blktap/blktap.c in Xen before 3.4.0 for the Linux kernel 2.6.18, and possibly other versions, allows guest OS users to cause a denial o...Show more
The do_block_io_op function in (1) drivers/xen/blkback/blkback.c and (2) drivers/xen/blktap/blktap.c in Xen before 3.4.0 for the Linux kernel 2.6.18, and possibly other versions, allows guest OS users to cause a denial of service (infinite loop and CPU consumption) via a large production request index to the blkback or blktap back-end drivers. NOTE: some of these details are obtained from third party information.Show less
1Citrix
1Web Interface
Apr 29, 2026
Dec 9, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Citrix Web Interface 5.0, 5.1, and 5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-6477 and...Show more
Cross-site scripting (XSS) vulnerability in Citrix Web Interface 5.0, 5.1, and 5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-6477 and CVE-2009-2454.Show less
1Citrix
1Xen
Apr 29, 2026
Dec 8, 2010
N/A· v4
N/A· v3
2.7 LOW· v2
The backend driver in Xen 3.x allows guest OS users to cause a denial of service via a kernel thread leak, which prevents the device and guest OS from being shut down or create a zombie domain, causes a hang in zenwatch,...Show more
The backend driver in Xen 3.x allows guest OS users to cause a denial of service via a kernel thread leak, which prevents the device and guest OS from being shut down or create a zombie domain, causes a hang in zenwatch, or prevents unspecified xm commands from working properly, related to (1) netback, (2) blkback, or (3) blktap.Show less
1Citrix
1Online Plug In For Windows For Xenapp & Xendesktop
Apr 29, 2026
Aug 11, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
The IICAClient interface in the ICAClient library in the ICA Client ActiveX Object (aka ICO) component in Citrix Online Plug-in for Windows for XenApp & XenDesktop before 12.0.3 allows remote attackers to execute arbitra...Show more
The IICAClient interface in the ICAClient library in the ICA Client ActiveX Object (aka ICO) component in Citrix Online Plug-in for Windows for XenApp & XenDesktop before 12.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HTML document that triggers the reading of a .ICA file.Show less
1Citrix
5Ica Client For Linux
Ica Client For SolarisOnline Plug In For Mac For Xenapp & Xendesktop+2 more
Apr 29, 2026
Aug 11, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Citrix Online Plug-in for Windows for XenApp & XenDesktop before 11.2, Citrix Online Plug-in for Mac for XenApp & XenDesktop before 11.0, Citrix ICA Client for Linux before 11.100, Citrix ICA Client for Solaris before 8....Show more
Citrix Online Plug-in for Windows for XenApp & XenDesktop before 11.2, Citrix Online Plug-in for Mac for XenApp & XenDesktop before 11.0, Citrix ICA Client for Linux before 11.100, Citrix ICA Client for Solaris before 8.63, and Citrix Receiver for Windows Mobile before 11.5 allow remote attackers to execute arbitrary code via (1) a crafted HTML document, (2) a crafted .ICA file, or (3) a crafted type field in an ICA graphics packet, related to a "heap offset overflow" issue.Show less
1Citrix
1Xenserver
Apr 29, 2026
Jul 2, 2010
N/A· v4
N/A· v3
1.9 LOW· v2
Citrix XenServer 5.0 Update 2 and earlier, and 5.5 Update 1 and earlier, when using a pvops kernel, allows guest users to cause a denial of service in the host via unspecified vectors that trigger "incorrectly set flags....Show more
Citrix XenServer 5.0 Update 2 and earlier, and 5.5 Update 1 and earlier, when using a pvops kernel, allows guest users to cause a denial of service in the host via unspecified vectors that trigger "incorrectly set flags."Show less
1Citrix
1Xenserver
Apr 29, 2026
Feb 12, 2010
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Unspecified vulnerability in Citrix XenServer 5.0 Update 3 and earlier, and 5.5, allows local users to bypass authentication and execute unspecified Xen API (XAPI) calls via unknown vectors.
1Citrix
3Online Plug In For Mac
Online Plug In For WindowsReceiver For Iphone
Apr 23, 2026
Nov 13, 2009
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Unspecified vulnerability in Citrix Online Plug-in for Windows 11.0.x before 11.0.150 and 11.x before 11.2, Online Plug-in for Mac before 11.0, Receiver for iPhone before 1.0.3, and ICA Java, Mac, UNIX, and Windows Clien...Show more
Unspecified vulnerability in Citrix Online Plug-in for Windows 11.0.x before 11.0.150 and 11.x before 11.2, Online Plug-in for Mac before 11.0, Receiver for iPhone before 1.0.3, and ICA Java, Mac, UNIX, and Windows Clients for XenApp and XenDesktop allows remote attackers to impersonate the SSL/TLS server and bypass authentication via a crafted certificate, a different vulnerability than CVE-2009-3555.Show less
1Citrix
1Xencenterweb
Apr 23, 2026
Oct 22, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to inject arbitrary PHP code into include/config.ini.php via t...Show more
Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to inject arbitrary PHP code into include/config.ini.php via the pool1 parameter. NOTE: some of these details are obtained from third party information.Show less
1Citrix
1Xencenterweb
Apr 23, 2026
Oct 22, 2009
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to hijack the authentication of administrators for (1) requests that c...Show more
Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to hijack the authentication of administrators for (1) requests that change the password via the username parameter to config/changepw.php or (2) stop a virtual machine via the stop_vmname parameter to hardstopvm.php. NOTE: some of these details are obtained from third party information.Show less
1Citrix
1Xencenterweb
Apr 23, 2026
Oct 22, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.php in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these deta...Show more
SQL injection vulnerability in login.php in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.Show less
1Citrix
1Xencenterweb
Apr 23, 2026
Oct 22, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to conf...Show more
Multiple cross-site scripting (XSS) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to config/edituser.php; (2) location, (3) sessionid, and (4) vmname parameters to console.php; (5) vmrefid and (6) vmname parameters to forcerestart.php; and (7) vmname and (8) vmrefid parameters to forcesd.php. NOTE: some of these details are obtained from third party information.Show less
1Citrix
1Web Interface
Apr 23, 2026
Jul 14, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Citrix Web Interface 4.6, 5.0, and 5.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Citrix
2Presentation Server
Xenapp
Apr 23, 2026
Jul 14, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Citrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Advanced Edition filters, which allows attackers to bypass intended access...Show more
Citrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Advanced Edition filters, which allows attackers to bypass intended access restrictions via unknown vectors.Show less
1Citrix
1Licensing
Apr 23, 2026
Jul 14, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in Citrix Licensing 11.5 have unknown impact and attack vectors, related to "underlying components of the License Management Console."
1Citrix
1Secure Gateway
Apr 23, 2026
Jun 25, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Secure Gateway service in Citrix Secure Gateway 3.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an unspecified request.
1Citrix
2Netscaler Access Gateway
Netscaler Access Gateway Firmware
Apr 23, 2026
Jun 25, 2009
N/A· v4
6.5 MEDIUM· v3
6.3 MEDIUM· v2
The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Authorization Action optio...Show more
The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Authorization Action option, which might allow remote authenticated users to bypass intended access restrictions.Show less
1Citrix
1Web Interface
Apr 23, 2026
Jun 8, 2009
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The disconnection feature in Citrix Web Interface 5.0 and 5.0.1 for Java Application Servers does not properly terminate a user's web interface session, which allows attackers with access to the same browser instance to...Show more
The disconnection feature in Citrix Web Interface 5.0 and 5.0.1 for Java Application Servers does not properly terminate a user's web interface session, which allows attackers with access to the same browser instance to gain access to the user's Web Interface session. NOTE: the attacker must also have valid credentials to the Web Interface.Show less
1Citrix
1Presentation Server Client
Apr 23, 2026
Mar 31, 2009
N/A· v4
N/A· v3
1.9 LOW· v2
Citrix Presentation Server Client for Windows before 10.200 does not clear "credential information" from process memory in unspecified circumstances, which might allow local users to gain privileges.