CVE-2010-0633
published 2010-02-12CVE-2010-0633: Unspecified vulnerability in Citrix XenServer 5.0 Update 3 and earlier, and 5.5, allows local users to bypass authentication and execute unspecified Xen API…
PriorityP418medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.35%
27.4th percentile
Unspecified vulnerability in Citrix XenServer 5.0 Update 3 and earlier, and 5.5, allows local users to bypass authentication and execute unspecified Xen API (XAPI) calls via unknown vectors.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | xenserver | <= 5.0 | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
CVE-2010-0633: Unspecified vulnerability in Citrix XenServer 5.0 Update 3 and earlier, and 5.5, allows local users to bypass authentication and execute unspecified X
vendor_citrix·2010-02-12·CVSS 4.6
CVE-2010-0633 [MEDIUM] CVE-2010-0633: Unspecified vulnerability in Citrix XenServer 5.0 Update 3 and earlier, and 5.5, allows local users to bypass authentication and execute unspecified X
CVE-2010-0633: Unspecified vulnerability in Citrix XenServer 5.0 Update 3 and earlier, and 5.5, allows local users to bypass authentication and execute unspecified Xen API (XAPI) calls via unknown vectors.
Citrix
Citrix Security Bulletin CTX123460
vendor_citrix·CVSS 4.6
CVE-2010-0633 [MEDIUM] Citrix Security Bulletin CTX123460
Citrix Security Bulletin CTX123460
CVE References: CVE-2010-0633, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX123456
vendor_citrix·CVSS 4.6
CVE-2010-0633 [MEDIUM] Citrix Security Bulletin CTX123456
Citrix Security Bulletin CTX123456
CVE References: CVE-2010-0633, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX123193
vendor_citrix·CVSS 4.6
CVE-2010-0633 [MEDIUM] Citrix Security Bulletin CTX123193
Citrix Security Bulletin CTX123193
CVE References: CVE-2010-0633, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
GHSA
GHSA-w686-r764-pjr6: Unspecified vulnerability in Citrix XenServer 5
ghsa_unreviewed·2022-05-02
CVE-2010-0633 [MEDIUM] GHSA-w686-r764-pjr6: Unspecified vulnerability in Citrix XenServer 5
Unspecified vulnerability in Citrix XenServer 5.0 Update 3 and earlier, and 5.5, allows local users to bypass authentication and execute unspecified Xen API (XAPI) calls via unknown vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-0428 libspice: Insufficient guest provided pointers validation
bugzilla·2010-02-26·CVSS 6.6
CVE-2010-0428 [MEDIUM] CVE-2010-0428 libspice: Insufficient guest provided pointers validation
CVE-2010-0428 libspice: Insufficient guest provided pointers validation
Izik Eidus found a bug in QEMU that allows priviledged guest user
to touch arbitrary memory in the hosting QEMU process. The bug is in
QXL/libspice code. Guest and host share region of memory and
use it to communicate with each other. Malicious user can use the
lack of validation of pointers embedded into data structures in
this memory area to touch host's abitrary memory location and/or make
the hosting QEMU process crash by dereferencing invalid pointer.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0633 https://rhn.redhat.com/errata/RHSA-2010-0633.html
---
This issue has been addressed in following products:
Red Hat Enterprise Virtualization for RHE
Bugzilla
CVE-2010-0429 libspice: Relying on guest provided data structures to indicate memory allocation
bugzilla·2010-02-26·CVSS 6.6
CVE-2010-0429 [MEDIUM] CVE-2010-0429 libspice: Relying on guest provided data structures to indicate memory allocation
CVE-2010-0429 libspice: Relying on guest provided data structures to indicate memory allocation
Izik Eidus found a bug in QEMU that allows priviledged guest user
to force QEMU process on the host to issue free() and/or malloc() calls at
addresses controlled by the guest user. The bug is in QXL/libspice code.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0633 https://rhn.redhat.com/errata/RHSA-2010-0633.html
---
This issue has been addressed in following products:
Red Hat Enterprise Virtualization for RHEL-5
Via RHSA-2010:0622 https://rhn.redhat.com/errata/RHSA-2010-0622.html
http://secunia.com/advisories/38431http://support.citrix.com/article/CTX123193http://support.citrix.com/article/CTX123456http://support.citrix.com/article/CTX123460http://www.securityfocus.com/bid/38052http://www.securitytracker.com/id?1023530http://www.vupen.com/english/advisories/2010/0290http://secunia.com/advisories/38431http://support.citrix.com/article/CTX123193http://support.citrix.com/article/CTX123456http://support.citrix.com/article/CTX123460http://www.securityfocus.com/bid/38052http://www.securitytracker.com/id?1023530http://www.vupen.com/english/advisories/2010/0290
2010-02-12
Published