Vulnerabilities > Citrix > Xendesktop > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2016-06-01 | CVE-2016-4810 | Improper Access Control vulnerability in Citrix Xenapp and Xendesktop Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenDesktop Delivery Controller via unspecified vectors. | 5.0 |
2014-07-11 | CVE-2014-4700 | Permissions, Privileges, and Access Controls vulnerability in Citrix Xendesktop Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user's desktop via unspecified vectors. | 4.9 |
2013-11-05 | CVE-2013-6077 | Permissions, Privileges, and Access Controls vulnerability in Citrix Xendesktop 7.0 Citrix XenDesktop 7.0, when upgraded from XenDesktop 5.x, does not properly enforce policy rule permissions, which allows remote attackers to bypass intended restrictions. | 5.8 |
2012-12-26 | CVE-2012-6314 | Local Security Bypass vulnerability in Citrix Xendesktop 5.6 Citrix XenDesktop Virtual Desktop Agent (VDA) 5.6.x before 5.6.200, when making changes to the server-side policy that control USB redirection, does not propagate changes to the VDA, which allows authenticated users to retain access to the USB device. | 5.0 |