Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
xenmobile server vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv3
CVE-2022-26151
Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.
Citrix Xenmobile Server 10.13.0
Citrix Xenmobile Server 10.14.0
7.8
CVSSv3
CVE-2018-10650
There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
Citrix Xenmobile Server 10.8
Citrix Xenmobile Server 10.7
6.1
CVSSv3
CVE-2018-10651
There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
Citrix Xenmobile Server 10.8
Citrix Xenmobile Server 10.7
8.8
CVSSv3
CVE-2021-44519
In Citrix XenMobile Server up to and including 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.
Citrix Xenmobile Server 10.13.0
Citrix Xenmobile Server 10.14.0
8.8
CVSSv3
CVE-2021-44520
In Citrix XenMobile Server up to and including 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.
Citrix Xenmobile Server 10.13.0
Citrix Xenmobile Server 10.14.0
8.1
CVSSv3
CVE-2018-10654
There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
Citrix Xenmobile Server 10.8
Citrix Xenmobile Server 10.7
9.1
CVSSv3
CVE-2018-18571
An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any Mobile Application Management (MAM) enrolled device.
Citrix Xenmobile Server 10.8.0
Citrix Xenmobile Server 10.9.0
5.3
CVSSv3
CVE-2016-6877
Citrix XenMobile Server prior to 10.5.0.24 allows man-in-the-middle malicious users to trigger HTTP 302 redirections via vectors involving the HTTP Host header and a cached page. NOTE: the vendor reports "our internal analysis of this issue concluded that this was not a vali...
Citrix Xenmobile Server
7.8
CVSSv3
CVE-2018-18013
* Xen Mobile up to and including 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If this service is supplied with raw serialised Java objects, it deserialises them back into Java objects in memory, giving rise to a remote c...
Citrix Xenmobile Server
7.8
CVSSv3
CVE-2018-18014
* Lack of authentication in Citrix Xen Mobile up to and including 10.8 allows low-privileged local users to execute system commands as root by making requests to private services listening on ports 8000, 30000 and 30001. NOTE: the vendor disputes that this is a vulnerability, sta...
Citrix Xenmobile Server
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
encryption
CVE-2024-4331
CVE-2024-26925
arbitrary code
CVE-2006-4304
CVE-2024-25458
CVE-2024-27077
reflected XSS
CVE-2024-4059
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »