Vulnerabilities (CVE)

Filtered by vendor Citrix Subscribe
Total 425 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-6573 1 Citrix 1 Access Gateway 2025-04-09 6.0 MEDIUM N/A
Unspecified vulnerability in Citrix Access Gateway 4.5 Advanced Edition, and 4.2 with Advanced Access Control (AAC) 4.2, when deployed on the Access Gateway appliance 4.2 through 4.2.2 allows remote authenticated users to "gain access to data" and obtain sensitive information via unspecified vectors.
CVE-2009-2452 1 Citrix 1 Licensing 2025-04-09 10.0 HIGH N/A
Multiple unspecified vulnerabilities in Citrix Licensing 11.5 have unknown impact and attack vectors, related to "underlying components of the License Management Console."
CVE-2009-2453 1 Citrix 2 Presentation Server, Xenapp 2025-04-09 7.5 HIGH N/A
Citrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Advanced Edition filters, which allows attackers to bypass intended access restrictions via unknown vectors.
CVE-2009-3760 1 Citrix 1 Xencenterweb 2025-04-09 7.5 HIGH N/A
Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to inject arbitrary PHP code into include/config.ini.php via the pool1 parameter. NOTE: some of these details are obtained from third party information.
CVE-2008-5716 1 Citrix 1 Xen 2025-04-09 7.2 HIGH N/A
xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue exists because of erroneous set_permissions calls in the fix for CVE-2008-4405.
CVE-2019-19781 1 Citrix 6 Application Delivery Controller, Application Delivery Controller Firmware, Gateway and 3 more 2025-04-03 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
CVE-2005-4412 1 Citrix 1 Program Neighborhood Client 2025-04-03 2.1 LOW N/A
Citrix Program Neighborhood client before 9.150 caches the user password in plaintext in the GUI while asterisks are used to visually obfuscate the password, which allows attackers with access to the session to obtain the password by using a tool to directly access the field.
CVE-2001-0908 1 Citrix 1 Metaframe 2025-04-03 7.5 HIGH N/A
CITRIX Metaframe 1.8 logs the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through Network Address Translation (NAT).
CVE-2002-2426 1 Citrix 3 Access Essentials, Metaframe Presentation Server, Presentation Server 2025-04-03 4.3 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in Citrix Presentation Server 4.0 and 4.5, MetaFrame Presentation Server 3.0, and Access Essentials 1.0 through 2.0 allows remote attackers to execute arbitrary published applications, and possibly other programs, as authenticated users via the InitialProgram key in an ICA connection. NOTE: some of these details are obtained from third party information.
CVE-2004-1902 1 Citrix 1 Metaframe Password Manager 2025-04-03 2.1 LOW N/A
The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information.
CVE-2005-3134 1 Citrix 1 Metaframe 2025-04-03 7.5 HIGH N/A
Citrix Metaframe Presentation Server 3.0 and 4.0 allows remote attackers to bypass policy restrictions by downloading the launch.ica file and changing the client device name (ClientName).
CVE-2005-3652 1 Citrix 1 Ica Program Neighborhood Client 2025-04-03 7.5 HIGH N/A
Heap-based buffer overflow in Citrix Program Neighborhood client 9.0 and earlier allows remote attackers to execute arbitrary code via a long name value in an Application Set response.
CVE-2006-4846 1 Citrix 1 Access Gateway 2025-04-03 5.1 MEDIUM N/A
Unspecified vulnerability in Citrix Access Gateway with Advanced Access Control (AAC) 4.2 before 20060914, when AAC is configured to use LDAP authentication, allows remote attackers to bypass authentication via unknown vectors.
CVE-2002-0301 1 Citrix 1 Nfuse 2025-04-03 5.0 MEDIUM N/A
Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters.
CVE-2001-0716 1 Citrix 1 Metaframe 2025-04-03 5.0 MEDIUM N/A
Citrix MetaFrame 1.8 Server with Service Pack 3, and XP Server Service Pack 1 and earlier, allows remote attackers to cause a denial of service (crash) via a large number of incomplete connections to the server.
CVE-2001-0760 1 Citrix 1 Nfuse 2025-04-03 5.0 MEDIUM N/A
Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not provide the session field.
CVE-2004-1077 1 Citrix 2 Metaframe Client, Program Neighborhood Agent 2025-04-03 5.0 MEDIUM N/A
Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and MetaFrame Presentation Server client for WinCE before 8.33 allows remote servers to create arbitrary shortcuts on the client via a full UNC path in the AppInStartmenu directive.
CVE-2005-0821 1 Citrix 1 Metaframe Conferencing Manager 2025-04-03 7.5 HIGH N/A
Unknown vulnerability in Citrix MetaFrame Conferencing Manager 3.0 allows conference members to bypass organizer restrictions to control the keyboard and mouse.
CVE-2004-1078 1 Citrix 2 Metaframe Client, Program Neighborhood Agent 2025-04-03 7.5 HIGH N/A
Stack-based buffer overflow in the client for Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and Citrix MetaFrame Presentation Server client for WinCE before 8.33 allows remote attackers to execute arbitrary code via a long cached icon filename in the InName XML element.
CVE-2002-0502 1 Citrix 1 Nfuse 2025-04-03 5.0 MEDIUM N/A
Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page.