CVE-2010-2990
https://notcve.org/view.php?id=CVE-2010-2990
Citrix Online Plug-in for Windows for XenApp & XenDesktop before 11.2, Citrix Online Plug-in for Mac for XenApp & XenDesktop before 11.0, Citrix ICA Client for Linux before 11.100, Citrix ICA Client for Solaris before 8.63, and Citrix Receiver for Windows Mobile before 11.5 allow remote attackers to execute arbitrary code via (1) a crafted HTML document, (2) a crafted .ICA file, or (3) a crafted type field in an ICA graphics packet, related to a "heap offset overflow" issue. Citrix Online Plug-in para Windows para XenApp & XenDesktop anterior v11.2, Citrix Online Plug-in para Mac para XenApp & XenDesktop anterior v11.0, Citrix ICA Client para Linux anterior v11.100, Citrix ICA Client para Solaris anterior v8.63, y Citrix Receiver para Windows Mobile before v11.5 permite a atacantes remotos ejecutar código de su elección a través de (1) un documento HTML manipulado, (2) un fichero .ICA manipulado, o (3) un tipo de campo manipulado, en un paquete gráfico ICA, relacionado con el tema de "desbordamiento de pila offset". • http://archives.neohapsis.com/archives/fulldisclosure/2010-08/0040.html http://secunia.com/advisories/40808 http://support.citrix.com/article/CTX125975 http://www.securityfocus.com/archive/1/512861/100/0/threaded • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2009-3936
https://notcve.org/view.php?id=CVE-2009-3936
Unspecified vulnerability in Citrix Online Plug-in for Windows 11.0.x before 11.0.150 and 11.x before 11.2, Online Plug-in for Mac before 11.0, Receiver for iPhone before 1.0.3, and ICA Java, Mac, UNIX, and Windows Clients for XenApp and XenDesktop allows remote attackers to impersonate the SSL/TLS server and bypass authentication via a crafted certificate, a different vulnerability than CVE-2009-3555. Vulnerabilidad no especificada en Citrix Online Plug-in para Windows 11.0.x en versiones anteriores a la 11.0.150 y 11.x en versiones anteriores a la 11.2, Online Plug-in para Mac en versiones anteriores a la 11.0, Receiver para iPhone en versiones anteriores a la 1.0.3, y cliente ICA Java, Mac, UNIX, y Windows para XenApp y XenDesktop permite a atacantes remotos hacerse pasar por el servidor SSL/TLS y eludir la autenticación mediante un certificado manipulado, una vulnerabilidad diferente a CVE-2009-3555. • http://secunia.com/advisories/37319 http://support.citrix.com/article/CTX123248 http://www.securityfocus.com/bid/37073 http://www.securitytracker.com/id?1023168 http://www.vupen.com/english/advisories/2009/3206 https://exchange.xforce.ibmcloud.com/vulnerabilities/54213 • CWE-310: Cryptographic Issues •