Xenapp

Vendor:

First CVE: Oct 22, 2008 · Active for 17 years

9
Total CVEs
More Total CVEs than 86% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 69% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Xenapp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 22, 2008
17 years ago
Most Recent CVE
Aug 5, 2021
1,815 days ago

CVE Severity & Scoring

Xenapp9 CVEs
All CVEs352,708 CVEs
MediumHighCritical
Attack Vector
Local1 (11.1%)
Network5 (55.6%)
Unknown3 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (66.7%)
High0 (0.0%)
Unknown3 (33.3%)
User Interaction
None6 (66.7%)
Unknown3 (33.3%)
Required0 (0.0%)
Privileges Required
Low3 (33.3%)
High0 (0.0%)
None3 (33.3%)
Unknown3 (33.3%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Citrix XenApp 6.x before 6.5 HRP07 and 7.x before 7.9 and Citrix XenDesktop before 7.9 might allow attackers to weaken an unspecified security mitigation via vectors related to mem
Aug 19, 20169.830NONO
The XML Service interface in Citrix XenApp 6.5 and 6.5 Feature Pack 1 allows remote attackers to execute arbitrary code via unspecified vectors.
Dec 26, 20129.329NONO
An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU
Nov 16, 20208.827NONO
A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix
Aug 5, 20217.825NONO
Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenD
Jun 1, 20167.524NONO
An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CT
Dec 14, 20208.822NONO
Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA error page only occurs after a va
Jun 11, 20205.321NONO
Citrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Advanced Edition filters, which all
Jul 14, 20097.519NONO
Unspecified vulnerability in Citrix XenApp (formerly Presentation Server) 4.5 Feature Pack 1 and earlier, Presentation Server 4.0, and Access Essentials 1.0, 1.5, and 2.0 allows lo
Oct 22, 20086.818NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Xenapp

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.8.0.019.82.2%00
7.7.0.019.82.2%00
7.6.0.019.82.2%00
7.638.52.2%00
7.5.0.019.82.2%00
7.517.50.9%00
7.1538.41.6%00
7.1.0.019.82.2%00
7.0.0.019.82.2%00
6.5.0.038.43.7%00
6.0.0.019.82.2%00
4.527.20.9%00