CVE-2016-9676
published 2017-01-18CVE-2016-9676: Buffer overflow in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.
PriorityP349critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.06%
89.5th percentile
Buffer overflow in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | xenserver | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
CVE-2016-9676: Buffer overflow in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.
vendor_citrix·2017-01-18·CVSS 9.8
CVE-2016-9676 [CRITICAL] CWE-119 CVE-2016-9676: Buffer overflow in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.
CVE-2016-9676: Buffer overflow in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.
Citrix
Citrix Security Bulletin CTX219580
vendor_citrix·CVSS 9.8
CVE-2016-9676 [CRITICAL] Citrix Security Bulletin CTX219580
Citrix Security Bulletin CTX219580
CVE References: CVE-2016-9676, CVE-2016-9677, CVE-2016-9678, CVE-2016-9679, CVE-2016-9680, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
VulDB
Citrix Provisioning Services up to 7.11 memory corruption (Nessus ID 96630 / BID-95620)
vuldb·2026-05-14·CVSS 9.8
CVE-2016-9676 [CRITICAL] Citrix Provisioning Services up to 7.11 memory corruption (Nessus ID 96630 / BID-95620)
A vulnerability has been found in Citrix Provisioning Services up to 7.11 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to memory corruption.
This vulnerability is referenced as CVE-2016-9676. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
GHSA
GHSA-27c7-r685-f6vw: Buffer overflow in Citrix Provisioning Services before 7
ghsa_unreviewed·2022-05-17
CVE-2016-9676 [CRITICAL] CWE-119 GHSA-27c7-r685-f6vw: Buffer overflow in Citrix Provisioning Services before 7
Buffer overflow in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-01-18
Published