Show filters
94 Total Results
Displaying 11-20 of 94
Sort by:
Attacker Value
Unknown

CVE-2020-8300

Disclosure Date: June 16, 2021 (last updated February 22, 2025)
Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a SAML SP or a SAML IdP for this to be possible.
Attacker Value
Very High

CVE-2014-6271

Disclosure Date: September 24, 2014 (last updated July 25, 2024)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
Attacker Value
Unknown

CVE-2023-4967

Disclosure Date: October 27, 2023 (last updated November 08, 2023)
Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server
Attacker Value
Unknown

CVE-2023-3467

Disclosure Date: July 19, 2023 (last updated October 08, 2023)
Privilege Escalation to root administrator (nsroot)
Attacker Value
Unknown

CVE-2023-3466

Disclosure Date: July 19, 2023 (last updated October 08, 2023)
Reflected Cross-Site Scripting (XSS)
Attacker Value
Unknown

CVE-2023-24487

Disclosure Date: July 10, 2023 (last updated November 08, 2023)
Arbitrary file read in Citrix ADC and Citrix Gateway 
Attacker Value
Unknown

CVE-2022-37719

Disclosure Date: January 23, 2023 (last updated October 08, 2023)
A Cross-Site Request Forgery (CSRF) in the management portal of JetNexus/EdgeNexus ADC 4.2.8 allows attackers to escalate privileges and execute arbitrary code via unspecified vectors.
Attacker Value
Unknown

CVE-2022-37718

Disclosure Date: January 23, 2023 (last updated October 08, 2023)
The management portal component of JetNexus/EdgeNexus ADC 4.2.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated attackers to execute arbitrary commands through a specially crafted payload. This vulnerability can also be exploited from an unauthenticated context via unspecified vectors
Attacker Value
Unknown

CVE-2019-18177

Disclosure Date: December 26, 2022 (last updated October 08, 2023)
In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update.
Attacker Value
Unknown

CVE-2022-27510

Disclosure Date: November 08, 2022 (last updated October 19, 2023)
Unauthorized access to Gateway user capabilities