Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2010-2990


Citrix Online Plug-in for Windows for XenApp & XenDesktop before 11.2, Citrix Online Plug-in for Mac for XenApp & XenDesktop before 11.0, Citrix ICA Client for Linux before 11.100, Citrix ICA Client for Solaris before 8.63, and Citrix Receiver for Windows Mobile before 11.5 allow remote attackers to execute arbitrary code via (1) a crafted HTML document, (2) a crafted .ICA file, or (3) a crafted type field in an ICA graphics packet, related to a "heap offset overflow" issue.


Published

2010-08-11T20:00:01.360

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 9.3 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application citrix ica_client_for_linux ≤ 11.0 Yes
Application citrix ica_client_for_solaris ≤ 8.62 Yes
Application citrix online_plug-in_for_mac_for_xenapp_\&_xendesktop ≤ 10.0 Yes
Application citrix online_plug-in_for_windows_for_xenapp_\&_xendesktop ≤ 11.1 Yes
Application citrix receiver_for_windows_mobile ≤ 11.0 Yes

References