Xenapp
Vendor:
First CVE: Oct 22, 2008 · Active for 17 years
9
Total CVEs
More Total CVEs than 86% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 69% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Xenapp over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 22, 2008
17 years ago
Most Recent CVE
Aug 5, 2021
1,815 days ago
CVE Severity & Scoring
Xenapp9 CVEs
22%
67%
11%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (11.1%)
Network5 (55.6%)
Unknown3 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (66.7%)
High0 (0.0%)
Unknown3 (33.3%)
User Interaction
None6 (66.7%)
Unknown3 (33.3%)
Required0 (0.0%)
Privileges Required
Low3 (33.3%)
High0 (0.0%)
None3 (33.3%)
Unknown3 (33.3%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-6493CRITICAL Citrix XenApp 6.x before 6.5 HRP07 and 7.x before 7.9 and Citrix XenDesktop before 7.9 might allow attackers to weaken an unspecified security mitigation via vectors related to mem | Aug 19, 2016 | 9.8 | 30 | NO | NO |
CVE-2012-5161HIGH The XML Service interface in Citrix XenApp 6.5 and 6.5 Feature Pack 1 allows remote attackers to execute arbitrary code via unspecified vectors. | Dec 26, 2012 | 9.3 | 29 | NO | NO |
CVE-2020-8269HIGH An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU | Nov 16, 2020 | 8.8 | 27 | NO | NO |
CVE-2021-22928HIGH A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix | Aug 5, 2021 | 7.8 | 25 | NO | NO |
CVE-2016-4810HIGH Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenD | Jun 1, 2016 | 7.5 | 24 | NO | NO |
CVE-2020-8283HIGH An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CT | Dec 14, 2020 | 8.8 | 22 | NO | NO |
CVE-2020-13998MEDIUM Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA error page only occurs after a va | Jun 11, 2020 | 5.3 | 21 | NO | NO |
CVE-2009-2453HIGH Citrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Advanced Edition filters, which all | Jul 14, 2009 | 7.5 | 19 | NO | NO |
CVE-2008-4676MEDIUM Unspecified vulnerability in Citrix XenApp (formerly Presentation Server) 4.5 Feature Pack 1 and earlier, Presentation Server 4.0, and Access Essentials 1.0, 1.5, and 2.0 allows lo | Oct 22, 2008 | 6.8 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Xenapp
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.8.0.0 | 1 | 9.8 | 2.2% | 0 | 0 |
| 7.7.0.0 | 1 | 9.8 | 2.2% | 0 | 0 |
| 7.6.0.0 | 1 | 9.8 | 2.2% | 0 | 0 |
| 7.6 | 3 | 8.5 | 2.2% | 0 | 0 |
| 7.5.0.0 | 1 | 9.8 | 2.2% | 0 | 0 |
| 7.5 | 1 | 7.5 | 0.9% | 0 | 0 |
| 7.15 | 3 | 8.4 | 1.6% | 0 | 0 |
| 7.1.0.0 | 1 | 9.8 | 2.2% | 0 | 0 |
| 7.0.0.0 | 1 | 9.8 | 2.2% | 0 | 0 |
| 6.5.0.0 | 3 | 8.4 | 3.7% | 0 | 0 |
| 6.0.0.0 | 1 | 9.8 | 2.2% | 0 | 0 |
| 4.5 | 2 | 7.2 | 0.9% | 0 | 0 |