Vulnerabilities > Citrix > Access Gateway > Critical

DATE CVE VULNERABILITY TITLE RISK
2011-07-21 CVE-2011-2882 Buffer Errors vulnerability in Citrix Access Gateway 8.1/9.0/9.1
Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 allows remote attackers to execute arbitrary code via crafted HTTP header data.
network
citrix CWE-119
critical
9.3
2011-07-21 CVE-2011-2883 Improper Input Validation vulnerability in Citrix Access Gateway 8.1/9.0/9.1
The NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 attempts to validate signed DLLs by checking the certificate subject, not the signature, which allows man-in-the-middle attackers to execute arbitrary code via HTTP header data referencing a DLL that was signed with a crafted certificate.
network
citrix CWE-20
critical
9.3
2011-01-14 CVE-2010-4566 Unspecified vulnerability in Citrix Access Gateway
The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers to execute arbitrary commands via shell metacharacters in the password field.
network
citrix
critical
9.3
2008-06-03 CVE-2008-2528 Improper Authentication vulnerability in Citrix Access Gateway 4.5.5/4.5.6
Unspecified vulnerability in Citrix Access Gateway Standard Edition 4.5.7 and earlier and Advanced Edition 4.5 HF2 and earlier allows attackers to bypass authentication and gain "access to network resources" via unspecified vectors.
network
low complexity
citrix CWE-287
critical
10.0
2007-07-26 CVE-2007-4013 Remote vulnerability in Citrix Access Gateway Standard and Advanced Edition
Multiple unspecified vulnerabilities in (1) Net6Helper.DLL (aka Net6Launcher Class) 4.5.2 and earlier, (2) npCtxCAO.dll (aka Citrix Endpoint Analysis Client) in a Firefox plugin directory, and (3) a second npCtxCAO.dll (aka CCAOControl Object) before 4.5.0.0 in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 have unknown impact and attack vectors, possibly related to buffer overflows.
network
citrix mozilla
critical
9.3