Vulnerabilities > Citrix > High

DATE CVE VULNERABILITY TITLE RISK
2017-08-24 CVE-2017-12134 Incorrect Calculation vulnerability in multiple products
The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and consequently obtain sensitive memory information, cause a denial of service, or gain host OS privileges by leveraging incorrect block IO merge-ability calculation.
local
low complexity
xen citrix CWE-682
7.2
2017-08-07 CVE-2015-7705 Improper Input Validation vulnerability in multiple products
The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.
network
low complexity
ntp netapp citrix siemens CWE-20
7.5
2017-01-23 CVE-2016-9383 Improper Input Validation vulnerability in multiple products
Xen, when running on a 64-bit hypervisor, allows local x86 guest OS users to modify arbitrary memory and consequently obtain sensitive information, cause a denial of service (host crash), or execute arbitrary code on the host by leveraging broken emulation of bit test instructions.
local
low complexity
xen citrix CWE-20
7.2
2017-01-18 CVE-2016-9679 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Citrix Provisioning Services
Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code by overwriting a function pointer.
network
low complexity
citrix CWE-119
7.5
2017-01-18 CVE-2016-9678 Use After Free vulnerability in Citrix Provisioning Services
Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.
network
low complexity
citrix CWE-416
7.5
2017-01-18 CVE-2016-9676 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Citrix Provisioning Services
Buffer overflow in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.
network
low complexity
citrix CWE-119
7.5
2016-09-26 CVE-2016-6276 Permissions, Privileges, and Access Controls vulnerability in Citrix Linux Virtual Delivery Agent
Citrix Linux Virtual Delivery Agent (aka VDA, formerly Linux Virtual Desktop) before 1.4.0 allows local users to gain root privileges via unspecified vectors.
local
low complexity
citrix CWE-264
7.2
2016-08-19 CVE-2016-6493 7PK - Security Features vulnerability in Citrix Xenapp and Xendesktop
Citrix XenApp 6.x before 6.5 HRP07 and 7.x before 7.9 and Citrix XenDesktop before 7.9 might allow attackers to weaken an unspecified security mitigation via vectors related to memory permission.
network
low complexity
citrix CWE-254
7.5
2016-08-02 CVE-2016-6258 Improper Access Control vulnerability in multiple products
The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.
local
low complexity
xen citrix CWE-284
7.2
2016-06-13 CVE-2016-5302 Improper Access Control vulnerability in Citrix Xenserver
Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a host by leveraging credentials for an Active Directory account.
network
low complexity
citrix CWE-284
7.5