Vulnerabilities > Citrix > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-01-26 CVE-2016-10025 NULL Pointer Dereference vulnerability in multiple products
VMFUNC emulation in Xen 4.6.x through 4.8.x on x86 systems using AMD virtualization extensions (aka SVM) allows local HVM guest OS users to cause a denial of service (hypervisor crash) by leveraging a missing NULL pointer check.
local
low complexity
xen citrix CWE-476
5.5
2017-01-26 CVE-2016-10024 Improper Input Validation vulnerability in multiple products
Xen through 4.8.x allows local x86 PV guest OS kernel administrators to cause a denial of service (host hang or crash) by modifying the instruction stream asynchronously while performing certain kernel operations.
local
low complexity
xen citrix CWE-20
6.0
2017-01-23 CVE-2016-9385 Improper Input Validation vulnerability in multiple products
The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of service (host crash) by leveraging lack of canonical address checks.
local
low complexity
xen citrix CWE-20
6.0
2017-01-18 CVE-2016-9677 Information Exposure vulnerability in Citrix Provisioning Services
Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified vectors.
network
low complexity
citrix CWE-200
5.3
2016-11-07 CVE-2016-9111 Improper Access Control vulnerability in Citrix Receiver Desktop 4.5
Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication requirement by leveraging physical access to a VDI for temporary disconnection of a LAN cable.
low complexity
citrix CWE-284
6.8
2016-08-02 CVE-2016-6259 Improper Input Validation vulnerability in multiple products
Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check.
local
low complexity
xen citrix CWE-20
6.2
2016-07-13 CVE-2016-5109 Improper Access Control vulnerability in Citrix Worx Home and Xenmobile MDX Toolkit
Citrix Worx Home for iOS before 10.3.6 and XenMobile MDX Toolkit for iOS before 10.3.6 might allow physically proximate attackers to bypass in-application Apple Touch ID authentication via unspecified vectors, related to an application requiring re-authentication.
low complexity
citrix CWE-284
4.3
2016-06-17 CVE-2016-5433 Improper Input Validation vulnerability in Citrix IOS Receiver 6.1.5
Citrix iOS Receiver before 7.0 allows attackers to cause TLS certificates to be incorrectly validated via unspecified vectors.
local
low complexity
citrix CWE-20
6.1
2016-06-01 CVE-2016-4945 Cross-site Scripting vulnerability in Citrix Netscaler Gateway 11.0 Firmware 65.35
Cross-site scripting (XSS) vulnerability in vpn/js/gateway_login_form_view.js in Citrix NetScaler Gateway 11.0 before Build 66.11 allows remote attackers to inject arbitrary web script or HTML via the NSC_TMAC cookie.
network
low complexity
citrix CWE-79
6.1
2016-05-11 CVE-2016-3712 Integer Overflow or Wraparound vulnerability in multiple products
Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.
5.5