Vulnerabilities > Citrix > Critical

DATE CVE VULNERABILITY TITLE RISK
2018-07-27 CVE-2017-2620 Out-of-bounds Write vulnerability in multiple products
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue.
network
low complexity
qemu redhat citrix debian xen CWE-787
critical
9.9
2018-07-03 CVE-2017-2615 Out-of-bounds Write vulnerability in multiple products
Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue.
network
low complexity
qemu redhat citrix debian xen CWE-787
critical
9.1
2018-05-23 CVE-2018-10653 XXE vulnerability in Citrix Xenmobile Server 10.7/10.8
There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
network
low complexity
citrix CWE-611
critical
9.8
2018-05-23 CVE-2018-10648 Unrestricted Upload of File with Dangerous Type vulnerability in Citrix Xenmobile Server 10.7/10.8
There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
network
low complexity
citrix CWE-434
critical
9.8
2018-05-17 CVE-2018-7218 Unspecified vulnerability in Citrix products
The AppFirewall functionality in Citrix NetScaler Application Delivery Controller and NetScaler Gateway 10.5 before Build 68.7, 11.0 before Build 71.24, 11.1 before Build 58.13, and 12.0 before Build 57.24 allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
citrix
critical
9.8
2018-03-06 CVE-2018-6809 Unspecified vulnerability in Citrix products
NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to gain privilege on a target system.
network
low complexity
citrix
critical
9.8
2017-08-07 CVE-2015-7705 Improper Input Validation vulnerability in multiple products
The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.
network
low complexity
ntp netapp citrix siemens CWE-20
critical
9.8
2017-07-20 CVE-2017-6316 Unspecified vulnerability in Citrix Netscaler Sd-Wan
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie.
network
low complexity
citrix
critical
9.8
2017-01-18 CVE-2016-9679 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Citrix Provisioning Services
Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code by overwriting a function pointer.
network
low complexity
citrix CWE-119
critical
9.8
2017-01-18 CVE-2016-9678 Use After Free vulnerability in Citrix Provisioning Services
Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.
network
low complexity
citrix CWE-416
critical
9.8