Vulnerabilities > Citrix > Medium

DATE CVE VULNERABILITY TITLE RISK
2012-11-23 CVE-2012-3498 Improper Input Validation vulnerability in multiple products
PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host crash) and possibly read hypervisor or guest memory via vectors related to a missing range check of map->index.
local
low complexity
citrix xen CWE-20
5.6
2012-11-23 CVE-2012-3496 Configuration vulnerability in multiple products
XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when translating paging mode is not used, allows local PV OS guest kernels to cause a denial of service (BUG triggered and host crash) via invalid flags such as MEMF_populate_on_demand.
local
citrix xen CWE-16
4.7
2012-11-23 CVE-2012-3495 Improper Input Validation vulnerability in multiple products
The physdev_get_free_pirq hypercall in arch/x86/physdev.c in Xen 4.1.x and Citrix XenServer 6.0.2 and earlier uses the return value of the get_free_pirq function as an array index without checking that the return value indicates an error, which allows guest OS users to cause a denial of service (invalid memory write and host crash) and possibly gain privileges via unspecified vectors.
local
low complexity
citrix xen CWE-20
6.1
2011-08-12 CVE-2011-1583 Numeric Errors vulnerability in Citrix XEN
Multiple integer overflows in tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allow local users to cause a denial of service and possibly execute arbitrary code via a crafted paravirtualised guest kernel image that triggers (1) a buffer overflow during a decompression loop or (2) an out-of-bounds read in the loader involving unspecified length fields.
local
citrix CWE-189
6.9
2011-02-25 CVE-2011-1101 Denial Of Service vulnerability in Citrix Licensing Administration Console 11.6
Multiple unspecified vulnerabilities in a third-party component of the Citrix Licensing Administration Console 11.6, formerly License Management Console, allow remote attackers to (1) access unauthorized "license administration functionality" or (2) cause a denial of service via unknown vectors.
network
citrix
6.8
2011-01-25 CVE-2010-4255 Unspecified vulnerability in Citrix XEN
The fixup_page_fault function in arch/x86/traps.c in Xen 4.0.1 and earlier on 64-bit platforms, when paravirtualization is enabled, does not verify that kernel mode is used to call the handle_gdt_ldt_mapping_fault function, which allows guest OS users to cause a denial of service (host OS BUG_ON) via a crafted memory access.
low complexity
citrix
6.1
2010-12-09 CVE-2010-4515 Cross-Site Scripting vulnerability in Citrix web Interface
Cross-site scripting (XSS) vulnerability in Citrix Web Interface 5.0, 5.1, and 5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-6477 and CVE-2009-2454.
network
citrix CWE-79
4.3
2010-02-12 CVE-2010-0633 Authentication Bypass vulnerability in Citrix Xenserver 5.0/5.5
Unspecified vulnerability in Citrix XenServer 5.0 Update 3 and earlier, and 5.5, allows local users to bypass authentication and execute unspecified Xen API (XAPI) calls via unknown vectors.
local
low complexity
citrix
4.6
2009-11-13 CVE-2009-3936 Cryptographic Issues vulnerability in Citrix products
Unspecified vulnerability in Citrix Online Plug-in for Windows 11.0.x before 11.0.150 and 11.x before 11.2, Online Plug-in for Mac before 11.0, Receiver for iPhone before 1.0.3, and ICA Java, Mac, UNIX, and Windows Clients for XenApp and XenDesktop allows remote attackers to impersonate the SSL/TLS server and bypass authentication via a crafted certificate, a different vulnerability than CVE-2009-3555.
network
citrix CWE-310
5.8
2009-10-22 CVE-2009-3757 Cross-Site Scripting vulnerability in Citrix Xencenterweb
Multiple cross-site scripting (XSS) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to config/edituser.php; (2) location, (3) sessionid, and (4) vmname parameters to console.php; (5) vmrefid and (6) vmname parameters to forcerestart.php; and (7) vmname and (8) vmrefid parameters to forcesd.php.
network
citrix CWE-79
4.3