Show filters
22 Total Results
Displaying 11-20 of 22
Sort by:
Attacker Value
Unknown

CVE-2018-18013

Disclosure Date: October 24, 2018 (last updated November 08, 2023)
* Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If this service is supplied with raw serialised Java objects, it deserialises them back into Java objects in memory, giving rise to a remote code execution vulnerability. NOTE: the vendor disputes that this is a vulnerability, stating it is "already mitigated by the internal firewall that limits access to configuration services to localhost.
0
Attacker Value
Unknown

CVE-2018-18014

Disclosure Date: October 24, 2018 (last updated November 08, 2023)
* Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by making requests to private services listening on ports 8000, 30000 and 30001. NOTE: the vendor disputes that this is a vulnerability, stating it is "already mitigated by the internal firewall that limits access to configuration services to localhost.
0
Attacker Value
Unknown

CVE-2018-10648

Disclosure Date: May 23, 2018 (last updated November 26, 2024)
There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
0
Attacker Value
Unknown

CVE-2018-10654

Disclosure Date: May 23, 2018 (last updated November 26, 2024)
There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
0
Attacker Value
Unknown

CVE-2018-10649

Disclosure Date: May 23, 2018 (last updated November 26, 2024)
There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3.
0
Attacker Value
Unknown

CVE-2018-10652

Disclosure Date: May 23, 2018 (last updated November 26, 2024)
There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3.
0
Attacker Value
Unknown

CVE-2018-10650

Disclosure Date: May 23, 2018 (last updated November 26, 2024)
There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
0
Attacker Value
Unknown

CVE-2018-10653

Disclosure Date: May 23, 2018 (last updated November 26, 2024)
There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
0
Attacker Value
Unknown

CVE-2018-10651

Disclosure Date: May 23, 2018 (last updated November 26, 2024)
There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
0
Attacker Value
Unknown

CVE-2017-9231

Disclosure Date: June 16, 2017 (last updated November 26, 2024)
XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via unspecified vectors.
0