CVE-2010-2990
Summary
| CVE | CVE-2010-2990 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-08-11 20:00:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Citrix Online Plug-in for Windows for XenApp & XenDesktop before 11.2, Citrix Online Plug-in for Mac for XenApp & XenDesktop before 11.0, Citrix ICA Client for Linux before 11.100, Citrix ICA Client for Solaris before 8.63, and Citrix Receiver for Windows Mobile before 11.5 allow remote attackers to execute arbitrary code via (1) a crafted HTML document, (2) a crafted .ICA file, or (3) a crafted type field in an ICA graphics packet, related to a "heap offset overflow" issue. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Citrix | Ica Client For Linux | All | All | All | All |
| Application | Citrix | Ica Client For Solaris | All | All | All | All |
| Application | Citrix | Online Plug-in For Mac For Xenapp Xendesktop | All | All | All | All |
| Application | Citrix | Online Plug-in For Windows For Xenapp Xendesktop | All | All | All | All |
| Application | Citrix | Receiver For Windows Mobile | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Citrix XenApp Online Plug-in and ICA Clients Code Execution Vulnerability - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Vulnerability in Citrix Online Plug-Ins and ICA Clients Could Result in Arbitrary Code Execution | af854a3a-2127-422b-91ae-364da2661108 | support.citrix.com | Patch, Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| archives.neohapsis.com/archives/fulldisclosure/2010-08/0040.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.