Citrix
citrix
393 CVEs • 153 products
Products (153)
Click to collapseToggle
Products (153)
Click to collapse
CVEs (393)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Avaya Citrix2Broadcast Server Broadcast ServerApr 23, 2026 Jan 9, 2009 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in login.asp in Citrix Application Gateway - Broadcast Server (BCS) before 6.1, as used by Avaya AG250 - Broadcast Server before 2.0 and possibly other products, allows remote attackers to exe...Show more |
xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact...Show more |
1Citrix 1Deterministic Network Enhancer Apr 23, 2026 Nov 18, 2008 N/A· v4 N/A· v3 7.2 HIGH· v2 dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, and (3) SafeNet SoftRemote and HighAssurance Remote, allows local users...Show more |
1Citrix 2Desktop Server Presentation ServerApr 23, 2026 Nov 17, 2008 N/A· v4 N/A· v3 1.9 LOW· v2 The installation process for Citrix Presentation Server 4.5 and Desktop Server 1.0, when MSI logging is enabled, stores database credentials in MSI log files, which allows local users to obtain these credentials by readi...Show more |
1Citrix 3Access Essentials Presentation ServerXenappApr 23, 2026 Oct 22, 2008 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Unspecified vulnerability in Citrix XenApp (formerly Presentation Server) 4.5 Feature Pack 1 and earlier, Presentation Server 4.0, and Access Essentials 1.0, 1.5, and 2.0 allows local users to gain privileges via unknown...Show more |
xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM's write access within this tree, which allows guest OS users to cause a denia...Show more |
1Citrix 2Metaframe Presentation Server XpApr 23, 2026 Aug 6, 2008 N/A· v4 N/A· v3 7.2 HIGH· v2 Untrusted search path vulnerability in Citrix MetaFrame Presentation Server allows local users to gain privileges via a malicious icabar.exe placed in the search path. |
Cross-site scripting (XSS) vulnerability in the XenAPI HTTP interfaces in Citrix XenServer Express, Standard, and Enterprise Edition 4.1.0; Citrix XenServer Dell Edition (Express and Enterprise) 4.1.0; and HP integrated...Show more |
Unspecified vulnerability in Citrix Access Gateway Standard Edition 4.5.7 and earlier and Advanced Edition 4.5 HF2 and earlier allows attackers to bypass authentication and gain "access to network resources" via unspecif...Show more |
1Citrix 4Access Essentials Citrix Presentation ServerDesktop Server+1 moreApr 23, 2026 May 18, 2008 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Unspecified vulnerability in Citrix Presentation Server 4.5 and earlier, Citrix Access Essentials 2.0 and earlier, and Citrix Desktop Server 1.0 allows remote authenticated users to access unauthorized desktops via unkno...Show more |
1Citrix 3Access Essentials Desktop ServerPresentation ServerApr 23, 2026 May 18, 2008 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Unspecified vulnerability in SecureICA and ICA Basic encryption of Citrix Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 can cause clients to use weaker encryption settings...Show more |
1Citrix 4Access Essentials Desktop ServerMetaframe Presentation Server+1 moreApr 23, 2026 Jan 18, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in the Independent Management Architecture (IMA) service in Citrix Presentation Server (MetaFrame Presentation Server) 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 allows rem...Show more |
Cross-site scripting (XSS) vulnerability in the on-line help feature in Citrix Web Interface 2.0 and earlier, and NFuse, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
1Citrix 3Edgesight For Endpoints Edgesight For NetscalerEdgesight For Presentation ServerApr 23, 2026 Dec 7, 2007 N/A· v4 N/A· v3 2.1 LOW· v2 Citrix EdgeSight 4.2 and 4.5 for Presentation Server, EdgeSight 4.2 and 4.5 for Endpoints, and EdgeSight for NetScaler 1.0 and 1.1 do not properly store database credentials in configuration files, which allows local use...Show more |
The web management interface in Citrix NetScaler 8.0 build 47.8 stores the device's primary IP address in a cookie, which might allow remote attackers to obtain sensitive network configuration information if this address...Show more |
The web management interface in Citrix NetScaler 8.0 build 47.8 uses weak encryption (XOR of unpadded data) to store credentials within a cookie, which makes it easier for remote attackers to obtain cleartext credentials...Show more |
Cross-site scripting (XSS) vulnerability in ws/generic_api_call.pl in Citrix NetScaler 8.0 build 47.8 allows remote attackers to inject arbitrary web script or HTML via the standalone parameter and other unspecified para...Show more |
The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-dependent attackers to hijack sessions by readin...Show more |
Citrix Access Gateway Advanced Edition before firmware 4.5.5 allows attackers to redirect users to arbitrary web sites and conduct phishing attacks via unknown vectors. |
Cross-site request forgery (CSRF) vulnerability in the web-based administration console in Citrix Access Gateway before firmware 4.5.5 allows remote attackers to perform certain configuration changes as administrators. |