Unspecified vulnerability in Citrix Online Plug-in for Windows 11.0.x before 11.0.150 and 11.x before 11.2, Online Plug-in for Mac before 11.0, Receiver for iPhone before 1.0.3, and ICA Java, Mac, UNIX, and Windows Clients for XenApp and XenDesktop allows remote attackers to impersonate the SSL/TLS server and bypass authentication via a crafted certificate, a different vulnerability than CVE-2009-3555.
2009-11-13T16:30:00.233
2025-04-09T00:30:58.490
Deferred
CVSSv2: 5.8 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:P
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | citrix | online_plug-in_for_mac | ≤ 10.0 | Yes |
Application | citrix | online_plug-in_for_windows | ≤ 11.2 | Yes |
Application | citrix | online_plug-in_for_windows | 11.0 | Yes |
Application | citrix | online_plug-in_for_windows | 11.1 | Yes |
Application | citrix | receiver_for_iphone | ≤ 1.0 | Yes |