Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
427 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.2% | — | Citrix Provisioning Services | 18/1/2017 | 17/6/2026 | Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code by overwriting a function pointer. | |
| Modificada | Crítica (9.8) | 3.1% | — | Citrix Provisioning Services | 18/1/2017 | 17/6/2026 | Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (5.3) | 1.5% | — | Citrix Provisioning Services | 18/1/2017 | 17/6/2026 | Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified vectors. | |
| Modificada | Crítica (9.8) | 4.1% | — | Citrix Provisioning Services | 18/1/2017 | 17/6/2026 | Buffer overflow in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Citrix Receiver Desktop | 7/11/2016 | 17/6/2026 | Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication requirement by leveraging physical access to a VDI for temporary disconnection of a LAN cable. NOTE: as of 20161208, the vendor could not reproduce the issue, stating "the researcher was unable to… | |
| Modificada | Alta (8.8) | 1.8% | — | Citrix Netscaler Application Delivery Controller Firmware | 28/10/2016 | 17/6/2026 | Unauthorized redirect vulnerability in Citrix NetScaler ADC before 10.1 135.8, 10.5 61.11, 11.0 65.31/65.35F and 11.1 47.14 allows a remote attacker to steal session cookies of a legitimate AAA user via manipulation of Host header. | |
| Modificada | Alta (7.5) | 1.8% | — | Citrix License ServerCitrix License Server VPX | 7/10/2016 | 17/6/2026 | The lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) before 2015 SP5 and 2016 before R1 SP1, as used by Citrix License Server for Windows before 11.14.0.1 and Citrix License Server VPX before 11.14.0.1, allows remote attackers to cause a denial of service (crash) via a type 2F packet with a… | |
| Modificada | Alta (7.8) | 0.35% | — | Citrix Linux Virtual Delivery Agent | 26/9/2016 | 17/6/2026 | Citrix Linux Virtual Delivery Agent (aka VDA, formerly Linux Virtual Desktop) before 1.4.0 allows local users to gain root privileges via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.2% | — | Citrix XenappCitrix Xendesktop | 19/8/2016 | 17/6/2026 | Citrix XenApp 6.x before 6.5 HRP07 and 7.x before 7.9 and Citrix XenDesktop before 7.9 might allow attackers to weaken an unspecified security mitigation via vectors related to memory permission. | |
| Modificada | Media (6.2) | 0.64% | — | XENCitrix Xenserver | 2/8/2016 | 17/6/2026 | Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check. | |
| Modificada | Alta (8.8) | 0.40% | — | XENCitrix Xenserver | 2/8/2016 | 17/6/2026 | The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries. | |
| Modificada | Media (4.3) | 0.34% | — | Citrix Xenmobile MDX ToolkitCitrix Worx Home | 13/7/2016 | 17/6/2026 | Citrix Worx Home for iOS before 10.3.6 and XenMobile MDX Toolkit for iOS before 10.3.6 might allow physically proximate attackers to bypass in-application Apple Touch ID authentication via unspecified vectors, related to an application requiring re-authentication. | |
| Modificada | Media (6.1) | 0.42% | — | Citrix IOS Receiver | 17/6/2016 | 17/6/2026 | Citrix iOS Receiver before 7.0 allows attackers to cause TLS certificates to be incorrectly validated via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.6% | — | Citrix Xenserver | 13/6/2016 | 17/6/2026 | Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a host by leveraging credentials for an Active Directory account. | |
| Modificada | Media (6.1) | 1.9% | — | Citrix Netscaler Gateway 11.0 Firmware | 1/6/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in vpn/js/gateway_login_form_view.js in Citrix NetScaler Gateway 11.0 before Build 66.11 allows remote attackers to inject arbitrary web script or HTML via the NSC_TMAC cookie. | |
| Modificada | Alta (7.5) | 0.86% | — | Citrix XenappCitrix Xendesktop | 1/6/2016 | 17/6/2026 | Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenDesktop Delivery Controller via unspecified vectors. | |
| Modificada | Media (5.5) | 0.51% | — | Oracle VM ServerQemuCanonical Ubuntu LinuxDebian Linux+7 | 11/5/2016 | 17/6/2026 | Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode. | |
| Modificada | Alta (8.8) | 0.92% | — | Debian LinuxHP Helion OpenstackCanonical Ubuntu LinuxQemu+11 | 11/5/2016 | 17/6/2026 | The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue. | |
| Modificada | Alta (8.1) | 2.1% | — | Citrix Command Center | 14/4/2016 | 17/6/2026 | Multiple SQL injection vulnerabilities in the Administration Web UI servlets in Citrix Command Center before 5.1 Build 36.7 and 5.2 before Build 44.11 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (8.6) | 2.3% | — | Citrix XenserverXEN | 13/4/2016 | 17/6/2026 | Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains to obtain sensitive information from other domains via unspecified vectors. | |
| Modificada | Media (6.1) | 0.80% | — | Citrix Xenmobile Server | 7/4/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling Patch 4, and 10.3 before Rolling Patch 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.1) | 1.1% | — | Citrix Netscaler | 17/2/2016 | 17/6/2026 | The Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, 10.5.e before Build 59.1305.e, and 10.1 allows remote attackers to conduct clickjacking attacks via unspecified vectors. | |
| Modificada | Crítica (9.8) | 3.4% | — | Citrix Netscaler | 17/2/2016 | 17/6/2026 | Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, and 10.5.e before Build 59.1305.e allows remote attackers to gain privileges via unspecified NS Web GUI commands. | |
| Modificada | Media (6.3) | 1.3% | — | Citrix XenserverXEN | 22/1/2016 | 17/6/2026 | The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address in an INVVPID instruction, which triggers a hypervisor bug check. | |
| Modificada | Media (5) | 1.0% | — | Citrix Netscaler Service Delivery Appliance Service VMCitrix Netscaler Gateway FirmwareCitrix Netscaler Application Delivery Controller Firmware | 17/11/2015 | 17/6/2026 | The administration UI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allows attackers to obtain sensitive information via unspecified… |