{"api_version":"1","generated_at":"2026-07-23T07:38:57+00:00","cve":"CVE-2007-1196","urls":{"html":"https://cve.report/CVE-2007-1196","api":"https://cve.report/api/cve/CVE-2007-1196.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-1196","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-1196"},"summary":{"title":"CVE-2007-1196","description":"Unspecified vulnerability in Citrix Presentation Server Client for Windows before 10.0 allows remote web sites to execute arbitrary code via unspecified vectors, related to the implementation of ICA connectivity through proxy servers.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-03-02 21:18:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2007/0784","name":"http://www.vupen.com/english/advisories/2007/0784","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/798364","name":"http://www.kb.cert.org/vuls/id/798364","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Notes","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/33833","name":"http://osvdb.org/33833","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/24350","name":"http://secunia.com/advisories/24350","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Citrix Presentation Server Client Unspecified Code Execution - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/32754","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/32754","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/22762","name":"http://www.securityfocus.com/bid/22762","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Citrix Presentation Server Client Unspecified Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id?1017712","name":"http://www.securitytracker.com/id?1017712","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Citrix Presentation Server Client for Windows Lets Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.citrix.com/article/CTX112589","name":"http://support.citrix.com/article/CTX112589","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Vulnerability in Citrix Presentation Server Client for Windows could result in arbitrary code execution","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-1196","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-1196","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"1196","vulnerable":"1","versionEndIncluding":"9.200","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"citrix","cpe5":"presentation_server_client","cpe6":"*","cpe7":"*","cpe8":"windows","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:50:35.234Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"citrix-ica-code-execution(32754)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/32754"},{"name":"24350","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/24350"},{"name":"VU#798364","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/798364"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.citrix.com/article/CTX112589"},{"name":"1017712","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1017712"},{"name":"ADV-2007-0784","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/0784"},{"name":"33833","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/33833"},{"name":"22762","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/22762"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-02-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in Citrix Presentation Server Client for Windows before 10.0 allows remote web sites to execute arbitrary code via unspecified vectors, related to the implementation of ICA connectivity through proxy servers."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"citrix-ica-code-execution(32754)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/32754"},{"name":"24350","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/24350"},{"name":"VU#798364","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/798364"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.citrix.com/article/CTX112589"},{"name":"1017712","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1017712"},{"name":"ADV-2007-0784","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/0784"},{"name":"33833","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/33833"},{"name":"22762","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/22762"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-1196","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in Citrix Presentation Server Client for Windows before 10.0 allows remote web sites to execute arbitrary code via unspecified vectors, related to the implementation of ICA connectivity through proxy servers."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"citrix-ica-code-execution(32754)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/32754"},{"name":"24350","refsource":"SECUNIA","url":"http://secunia.com/advisories/24350"},{"name":"VU#798364","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/798364"},{"name":"http://support.citrix.com/article/CTX112589","refsource":"CONFIRM","url":"http://support.citrix.com/article/CTX112589"},{"name":"1017712","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1017712"},{"name":"ADV-2007-0784","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/0784"},{"name":"33833","refsource":"OSVDB","url":"http://osvdb.org/33833"},{"name":"22762","refsource":"BID","url":"http://www.securityfocus.com/bid/22762"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-1196","datePublished":"2007-03-02T19:00:00.000Z","dateReserved":"2007-03-02T00:00:00.000Z","dateUpdated":"2024-08-07T12:50:35.234Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-03-02 21:18:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:presentation_server_client:*:*:windows:*:*:*:*:*","versionEndIncluding":"9.200","matchCriteriaId":"A4D7FFE0-939F-4A9A-8FA2-B9AA812E87A7"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"1196","Ordinal":"1","Title":"CVE-2007-1196","CVE":"CVE-2007-1196","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"1196","Ordinal":"1","NoteData":"Unspecified vulnerability in Citrix Presentation Server Client for Windows before 10.0 allows remote web sites to execute arbitrary code via unspecified vectors, related to the implementation of ICA connectivity through proxy servers.","Type":"Description","Title":"CVE-2007-1196"},{"CveYear":"2007","CveId":"1196","Ordinal":"2","NoteData":"2007-03-02","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"1196","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}