Show filters
370 Total Results
Displaying 71-80 of 370
Sort by:
Attacker Value
Unknown

CVE-2021-22914

Disclosure Date: June 16, 2021 (last updated February 22, 2025)
Citrix Cloud Connector before 6.31.0.62192 suffers from insecure storage of sensitive information due to sensitive information being stored in the Citrix Cloud Connector installation log files. Such information could be used by an malicious actor to access a Citrix Cloud environment. This issue affects all versions of Citrix Cloud Connector that were installed by passing secure client parameters for installation via the command line. The issue does not affect Citrix Cloud Connector if it was installed using the interactive installer or where a parameter file was used with the command-line installer.
Attacker Value
Unknown

CVE-2021-22891

Disclosure Date: May 27, 2021 (last updated February 22, 2025)
A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.10.1 and 5.11.18 may allow unauthenticated remote compromise of the Storage Zones Controller.
Attacker Value
Unknown

CVE-2021-22907

Disclosure Date: May 27, 2021 (last updated February 22, 2025)
An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalation in CR versions prior to 2105 and 1912 LTSR prior to CU4.
Attacker Value
Unknown

CVE-2020-8274

Disclosure Date: January 06, 2021 (last updated February 22, 2025)
Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.
Attacker Value
Unknown

CVE-2020-8275

Disclosure Date: January 06, 2021 (last updated February 22, 2025)
Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.
Attacker Value
Unknown

CVE-2020-8258

Disclosure Date: December 14, 2020 (last updated February 22, 2025)
Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, allows an attacker to modify arbitrary files.
Attacker Value
Unknown

CVE-2020-8283

Disclosure Date: December 14, 2020 (last updated February 22, 2025)
An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9.
Attacker Value
Unknown

CVE-2020-8257

Disclosure Date: December 14, 2020 (last updated February 22, 2025)
Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, lead to privilege escalation attacks
Attacker Value
Unknown

CVE-2020-8270

Disclosure Date: November 16, 2020 (last updated February 22, 2025)
An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285871 and CTX285872, 7.15 LTSR CU6 hotfix CTX285341 and CTX285342
Attacker Value
Unknown

CVE-2020-8272

Disclosure Date: November 16, 2020 (last updated February 22, 2025)
Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8