Show filters
370 Total Results
Displaying 201-210 of 370
Sort by:
Attacker Value
Unknown

CVE-2016-9679

Disclosure Date: January 18, 2017 (last updated November 25, 2024)
Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code by overwriting a function pointer.
0
Attacker Value
Unknown

CVE-2016-9111

Disclosure Date: November 07, 2016 (last updated November 25, 2024)
Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication requirement by leveraging physical access to a VDI for temporary disconnection of a LAN cable. NOTE: as of 20161208, the vendor could not reproduce the issue, stating "the researcher was unable to provide us with information that would allow us to confirm the behaviour and, despite extensive investigation on test deployments of supported products, we were unable to reproduce the behaviour as he described. The researcher has also, despite additional requests for information, ceased to respond to us."
0
Attacker Value
Unknown

CVE-2016-9028

Disclosure Date: October 28, 2016 (last updated November 25, 2024)
Unauthorized redirect vulnerability in Citrix NetScaler ADC before 10.1 135.8, 10.5 61.11, 11.0 65.31/65.35F and 11.1 47.14 allows a remote attacker to steal session cookies of a legitimate AAA user via manipulation of Host header.
0
Attacker Value
Unknown

CVE-2016-6273

Disclosure Date: October 07, 2016 (last updated November 25, 2024)
The lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) before 2015 SP5 and 2016 before R1 SP1, as used by Citrix License Server for Windows before 11.14.0.1 and Citrix License Server VPX before 11.14.0.1, allows remote attackers to cause a denial of service (crash) via a type 2F packet with a '01 19' opcode.
0
Attacker Value
Unknown

CVE-2016-6276

Disclosure Date: September 26, 2016 (last updated November 25, 2024)
Citrix Linux Virtual Delivery Agent (aka VDA, formerly Linux Virtual Desktop) before 1.4.0 allows local users to gain root privileges via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-6493

Disclosure Date: August 19, 2016 (last updated November 25, 2024)
Citrix XenApp 6.x before 6.5 HRP07 and 7.x before 7.9 and Citrix XenDesktop before 7.9 might allow attackers to weaken an unspecified security mitigation via vectors related to memory permission.
0
Attacker Value
Unknown

CVE-2016-6258

Disclosure Date: August 02, 2016 (last updated November 25, 2024)
The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.
0
Attacker Value
Unknown

CVE-2016-6259

Disclosure Date: August 02, 2016 (last updated November 25, 2024)
Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check.
0
Attacker Value
Unknown

CVE-2016-5109

Disclosure Date: July 13, 2016 (last updated November 25, 2024)
Citrix Worx Home for iOS before 10.3.6 and XenMobile MDX Toolkit for iOS before 10.3.6 might allow physically proximate attackers to bypass in-application Apple Touch ID authentication via unspecified vectors, related to an application requiring re-authentication.
0
Attacker Value
Unknown

CVE-2016-5433

Disclosure Date: June 17, 2016 (last updated November 25, 2024)
Citrix iOS Receiver before 7.0 allows attackers to cause TLS certificates to be incorrectly validated via unspecified vectors.
0