VYPR

Xenmobile Server

by Citrix Systems

CVEs (22)

  • CVE-2016-6877MedMay 5, 2017
    risk 0.35cvss 5.3epss 0.01

    Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving the HTTP Host header and a cached page. NOTE: the vendor reports "our internal analysis of this issue concluded that this was not a valid…

  • CVE-2018-18014MedOct 24, 2018
    risk 0.31cvss 4.8epss 0.00

    * Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by making requests to private services listening on ports 8000, 30000 and 30001. NOTE: the vendor disputes that this is a vulnerability, stating it is…

Page 2 of 2