Filtered by vendor Citrix Subscriptions
Total 450 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2002-0503 1 Citrix 1 Nfuse 2025-04-03 N/A
Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter.
CVE-2006-4846 1 Citrix 1 Access Gateway 2025-04-03 N/A
Unspecified vulnerability in Citrix Access Gateway with Advanced Access Control (AAC) 4.2 before 20060914, when AAC is configured to use LDAP authentication, allows remote attackers to bypass authentication via unknown vectors.
CVE-2000-0244 1 Citrix 2 Metaframe, Winframe 2025-04-03 N/A
The Citrix ICA (Independent Computing Architecture) protocol uses weak encryption (XOR) for user authentication.
CVE-2005-3652 1 Citrix 1 Ica Program Neighborhood Client 2025-04-03 N/A
Heap-based buffer overflow in Citrix Program Neighborhood client 9.0 and earlier allows remote attackers to execute arbitrary code via a long name value in an Application Set response.
CVE-2001-0908 1 Citrix 1 Metaframe 2025-04-03 N/A
CITRIX Metaframe 1.8 logs the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through Network Address Translation (NAT).
CVE-2002-0301 1 Citrix 1 Nfuse 2025-04-03 N/A
Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters.
CVE-2001-0716 1 Citrix 1 Metaframe 2025-04-03 N/A
Citrix MetaFrame 1.8 Server with Service Pack 3, and XP Server Service Pack 1 and earlier, allows remote attackers to cause a denial of service (crash) via a large number of incomplete connections to the server.
CVE-2001-1192 1 Citrix 1 Ica Client 2025-04-03 N/A
Citrix Independent Computing Architecture (ICA) Client for Windows 6.1 allows remote malicious web sites to execute arbitrary code via a .ICA file, which is downloaded and automatically executed by the client.
CVE-2005-3134 1 Citrix 1 Metaframe 2025-04-03 N/A
Citrix Metaframe Presentation Server 3.0 and 4.0 allows remote attackers to bypass policy restrictions by downloading the launch.ica file and changing the client device name (ClientName).
CVE-2005-4412 1 Citrix 1 Program Neighborhood Client 2025-04-03 N/A
Citrix Program Neighborhood client before 9.150 caches the user password in plaintext in the GUI while asterisks are used to visually obfuscate the password, which allows attackers with access to the session to obtain the password by using a tool to directly access the field.
CVE-2001-0760 1 Citrix 1 Nfuse 2025-04-03 N/A
Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not provide the session field.
CVE-2022-27507 1 Citrix 2 Application Delivery Controller, Gateway 2025-04-01 6.5 Medium
Authenticated denial of service
CVE-2022-27508 1 Citrix 2 Application Delivery Controller, Gateway 2025-04-01 7.5 High
Unauthenticated denial of service
CVE-2024-6148 1 Citrix 1 Workspace 2025-03-25 8.8 High
Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5
CVE-2023-24485 1 Citrix 1 Workspace 2025-03-19 7.8 High
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.
CVE-2023-24484 1 Citrix 1 Workspace 2025-03-18 5.5 Medium
A malicious user can cause log files to be written to a directory that they do not have permission to write to.
CVE-2023-24483 2 Citrix, Microsoft 2 Virtual Apps And Desktops, Windows 2025-03-18 7.8 High
A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA.
CVE-2023-4967 1 Citrix 2 Netscaler Application Delivery Controller, Netscaler Gateway 2025-02-27 8.2 High
Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server
CVE-2023-31018 8 Canonical, Citrix, Linux and 5 more 9 Ubuntu Linux, Hypervisor, Linux Kernel and 6 more 2025-02-27 6.5 Medium
NVIDIA GPU Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a NULL-pointer dereference, which may lead to denial of service.
CVE-2023-31022 8 Canonical, Citrix, Linux and 5 more 9 Ubuntu Linux, Hypervisor, Linux Kernel and 6 more 2025-02-27 5.5 Medium
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a NULL-pointer dereference may lead to denial of service.