CVE-2010-2990 - CVE House
Back to Database
Status published Critical CVE-2010-2990

Citrix Online Plug-in for Windows for XenApp & XenDesktop before...

Vulnerability Description

Citrix Online Plug-in for Windows for XenApp & XenDesktop before 11.2, Citrix Online Plug-in for Mac for XenApp & XenDesktop before 11.0, Citrix ICA Client for Linux before 11.100, Citrix ICA Client for Solaris before 8.63, and Citrix Receiver for Windows Mobile before 11.5 allow remote attackers to execute arbitrary code via (1) a crafted HTML document, (2) a crafted .ICA file, or (3) a crafted type field in an ICA graphics packet, related to a "heap offset overflow" issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-2990

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

ica client for linux, ica client for solaris, online plug-in for mac for xenapp \& xendesktop, online plug-in for windows for xenapp \& xendesktop, receiver for windows mobile
Vulnerable Versions:
0

Timeline

Official Publish: August 11th, 2010
Last Modified: August 7th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.