Vulnerabilities (CVE)

Filtered by vendor Citrix Subscribe
Filtered by product Xenmobile Server
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-8208 1 Citrix 1 Xenmobile Server 2020-08-19 4.3 MEDIUM 6.1 MEDIUM
Improper input validation in Citrix XenMobile Server 10.12 before RP1, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.11 before RP6 and Citrix XenMobile Server before 10.9 RP5 allows Cross-Site Scripting (XSS).
CVE-2018-10651 1 Citrix 1 Xenmobile Server 2018-06-25 5.8 MEDIUM 6.1 MEDIUM
There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
CVE-2018-10649 1 Citrix 1 Xenmobile Server 2018-06-25 4.3 MEDIUM 6.1 MEDIUM
There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3.
CVE-2016-6877 1 Citrix 1 Xenmobile Server 2017-06-27 2.6 LOW 5.3 MEDIUM
** DISPUTED ** Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving the HTTP Host header and a cached page. NOTE: the vendor reports "our internal analysis of this issue concluded that this was not a valid vulnerability" because an exploitation scenario would involve a man-in-the-middle attack against a TLS session.
CVE-2016-2789 1 Citrix 1 Xenmobile Server 2016-12-03 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling Patch 4, and 10.3 before Rolling Patch 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.