Citrix / Netscaler
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2018-6186 | Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/read_url URI by an authenticated attacker who has a webapp account. The attack… | HIGH | 8.8 | Feb 1, 2018 |
| CVE-2016-2072 | The Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5… | MEDIUM | 6.1 | Feb 17, 2016 |
| CVE-2016-2071 | Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, and 10.5.e before Buil… | CRITICAL | 9.8 | Feb 17, 2016 |
| CVE-2015-2841 | Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restrictions via a crafted Content-Type header, as… | MEDIUM | 5.0 | Apr 3, 2015 |
| CVE-2015-2840 | Cross-site scripting (XSS) vulnerability in help/rt/large_search.html in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to inject arbitrary… | MEDIUM | 4.3 | Apr 3, 2015 |
| CVE-2015-2839 | The Nitro API in Citrix NetScaler before 10.5 build 52.3nc uses an incorrect Content-Type when returning an error message, which allows remote attackers to con… | MEDIUM | 4.3 | Apr 3, 2015 |
| CVE-2015-2838 | Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to hijack the authentication… | MEDIUM | 6.8 | Apr 3, 2015 |
| CVE-2007-6193 | The web management interface in Citrix NetScaler 8.0 build 47.8 stores the device's primary IP address in a cookie, which might allow remote attackers to obtai… | MEDIUM | 5.0 | Nov 30, 2007 |
| CVE-2007-6192 | The web management interface in Citrix NetScaler 8.0 build 47.8 uses weak encryption (XOR of unpadded data) to store credentials within a cookie, which makes i… | MEDIUM | 4.3 | Nov 30, 2007 |
| CVE-2007-6037 | Cross-site scripting (XSS) vulnerability in ws/generic_api_call.pl in Citrix NetScaler 8.0 build 47.8 allows remote attackers to inject arbitrary web script or… | MEDIUM | 4.3 | Nov 20, 2007 |
Showing 1 to 10 of 10 CVEs