Show filters
370 Total Results
Displaying 311-320 of 370
Sort by:
Attacker Value
Unknown
CVE-2009-2453
Disclosure Date: July 14, 2009 (last updated October 04, 2023)
Citrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Advanced Edition filters, which allows attackers to bypass intended access restrictions via unknown vectors.
0
Attacker Value
Unknown
CVE-2009-2454
Disclosure Date: July 14, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Citrix Web Interface 4.6, 5.0, and 5.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-2452
Disclosure Date: July 14, 2009 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in Citrix Licensing 11.5 have unknown impact and attack vectors, related to "underlying components of the License Management Console."
0
Attacker Value
Unknown
CVE-2009-2214
Disclosure Date: June 25, 2009 (last updated October 04, 2023)
The Secure Gateway service in Citrix Secure Gateway 3.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an unspecified request.
0
Attacker Value
Unknown
CVE-2009-2213
Disclosure Date: June 25, 2009 (last updated January 09, 2024)
The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Authorization Action option, which might allow remote authenticated users to bypass intended access restrictions.
0
Attacker Value
Unknown
CVE-2008-6830
Disclosure Date: June 08, 2009 (last updated October 04, 2023)
The disconnection feature in Citrix Web Interface 5.0 and 5.0.1 for Java Application Servers does not properly terminate a user's web interface session, which allows attackers with access to the same browser instance to gain access to the user's Web Interface session. NOTE: the attacker must also have valid credentials to the Web Interface.
0
Attacker Value
Unknown
CVE-2008-6561
Disclosure Date: March 31, 2009 (last updated October 04, 2023)
Citrix Presentation Server Client for Windows before 10.200 does not clear "credential information" from process memory in unspecified circumstances, which might allow local users to gain privileges.
0
Attacker Value
Unknown
CVE-2008-5882
Disclosure Date: January 09, 2009 (last updated October 04, 2023)
SQL injection vulnerability in login.asp in Citrix Application Gateway - Broadcast Server (BCS) before 6.1, as used by Avaya AG250 - Broadcast Server before 2.0 and possibly other products, allows remote attackers to execute arbitrary SQL commands via the txtUID parameter.
0
Attacker Value
Unknown
CVE-2008-5716
Disclosure Date: December 24, 2008 (last updated October 04, 2023)
xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue exists because of erroneous set_permissions calls in the fix for CVE-2008-4405.
0
Attacker Value
Unknown
CVE-2008-5121
Disclosure Date: November 18, 2008 (last updated October 04, 2023)
dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, and (3) SafeNet SoftRemote and HighAssurance Remote, allows local users to gain privileges via a crafted DNE_IOCTL DeviceIoControl request to the \\.\DNE device interface.
0