Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-2990

Опубликовано: 11 авг. 2010
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

Citrix Online Plug-in for Windows for XenApp & XenDesktop before 11.2, Citrix Online Plug-in for Mac for XenApp & XenDesktop before 11.0, Citrix ICA Client for Linux before 11.100, Citrix ICA Client for Solaris before 8.63, and Citrix Receiver for Windows Mobile before 11.5 allow remote attackers to execute arbitrary code via (1) a crafted HTML document, (2) a crafted .ICA file, or (3) a crafted type field in an ICA graphics packet, related to a "heap offset overflow" issue.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:citrix:ica_client_for_linux:*:*:*:*:*:*:*:*
Версия до 11.0 (включая)
cpe:2.3:a:citrix:ica_client_for_solaris:*:*:*:*:*:*:*:*
Версия до 8.62 (включая)
cpe:2.3:a:citrix:online_plug-in_for_mac_for_xenapp_\&_xendesktop:*:*:*:*:*:*:*:*
Версия до 10.0 (включая)
cpe:2.3:a:citrix:online_plug-in_for_windows_for_xenapp_\&_xendesktop:*:*:*:*:*:*:*:*
Версия до 11.1 (включая)
cpe:2.3:a:citrix:receiver_for_windows_mobile:*:*:*:*:*:*:*:*
Версия до 11.0 (включая)

EPSS

Процентиль: 90%
0.05518
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-119

Связанные уязвимости

github
больше 3 лет назад

Citrix Online Plug-in for Windows for XenApp & XenDesktop before 11.2, Citrix Online Plug-in for Mac for XenApp & XenDesktop before 11.0, Citrix ICA Client for Linux before 11.100, Citrix ICA Client for Solaris before 8.63, and Citrix Receiver for Windows Mobile before 11.5 allow remote attackers to execute arbitrary code via (1) a crafted HTML document, (2) a crafted .ICA file, or (3) a crafted type field in an ICA graphics packet, related to a "heap offset overflow" issue.

EPSS

Процентиль: 90%
0.05518
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-119