Vulnerabilities > Citrix > VDI IN A BOX > 5.3.0

DATE CVE VULNERABILITY TITLE RISK
2014-05-30 CVE-2014-3780 Improper Authentication vulnerability in Citrix Vdi-In-A-Box
Unspecified vulnerability in Citrix VDI-In-A-Box 5.3.x before 5.3.8 and 5.4.x before 5.4.4 allows remote attackers to bypass authentication via unspecified vectors, related to a Java servlet.
network
low complexity
citrix CWE-287
7.5
2014-04-15 CVE-2014-2690 Permissions, Privileges, and Access Controls vulnerability in Citrix Vdi-In-A-Box
Citrix VDI-in-a-Box 5.3.x before 5.3.6 and 5.4.x before 5.4.3 allows local users to obtain administrator credentials by reading the log.
local
low complexity
citrix CWE-264
2.1