CVE-2007-2850

The Session Reliability Service (XTE) in Citrix MetaFrame Presentation Server 3.0, Presentation Server 4.0, and Access Essentials 1.0 and 1.5, allows remote attackers to bypass network security policies and connect to arbitrary TCP ports via a modified address:port string. The vendor has addressed this issue with the following product updates: MetaFrame Presentation Server 3.0 for Windows 2000 Server: EN - http://support.citrix.com/article/CTX112818 FR - http://support.citrix.com/article/CTX112821 DE - http://support.citrix.com/article/CTX112819 JA - http://support.citrix.com/article/CTX112820 ES - http://support.citrix.com/article/CTX112822 MetaFrame Presentation Server 3.0 for Windows Server 2003: EN - http://support.citrix.com/article/CTX112813 FR - http://support.citrix.com/article/CTX112816 DE - http://support.citrix.com/article/CTX112814 JA - http://support.citrix.com/article/CTX112815 ES - http://support.citrix.com/article/CTX112817 Citrix Presentation Server 4.0 for Windows 2000 Server: EN - http://support.citrix.com/article/CTX112844 FR - http://support.citrix.com/article/CTX112847 DE - http://support.citrix.com/article/CTX112845 JA - http://support.citrix.com/article/CTX112848 ES - http://support.citrix.com/article/CTX112846 Citrix Presentation Server 4.0 for Windows Server 2003: EN - http://support.citrix.com/article/CTX112839 FR - http://support.citrix.com/article/CTX112842 DE - http://support.citrix.com/article/CTX112840 JA - http://support.citrix.com/article/CTX112843 ES - http://support.citrix.com/article/CTX112841 Citrix Presentation Server 4.0 for Windows Server 2003 x64 Editions: EN - http://support.citrix.com/article/CTX112886 FR - http://support.citrix.com/article/CTX112887 DE - http://support.citrix.com/article/CTX112888 JA - http://support.citrix.com/article/CTX112890 ES - http://support.citrix.com/article/CTX112889 Citrix Access Essentials 1.0: EN - http://support.citrix.com/article/CTX112839 FR - http://support.citrix.com/article/CTX112842 DE - http://support.citrix.com/article/CTX112840 ES - http://support.citrix.com/article/CTX112841 Citrix Access Essentials 1.5: EN - http://support.citrix.com/article/CTX112839 FR - http://support.citrix.com/article/CTX112842 DE - http://support.citrix.com/article/CTX112840 ES - http://support.citrix.com/article/CTX112841

Publication date: Thu, 24 May 2007 23:30:00 +0000


Cyber News related to CVE-2007-2850

CVE-2015-2503 - Microsoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2007 IME (Japanese) SP3, Access 2010 SP2, Excel 2010 SP2, InfoPath 2010 ...
6 years ago
CVE-2007-2850 - The Session Reliability Service (XTE) in Citrix MetaFrame Presentation Server 3.0, Presentation Server 4.0, and Access Essentials 1.0 and 1.5, allows remote attackers to bypass network security policies and connect to arbitrary TCP ports via a ...
7 years ago
CVE-2022-2850 - A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. ...
1 year ago
CVE-2005-2850 - SlimFTPd 3.17 allows remote attackers to cause a denial of service (crash) via certain (1) USER and (2) PASS commands, possibly due to a buffer overflow or off-by-one error. ...
16 years ago
CVE-2009-2850 - Multiple buffer overflows in NASA Common Data Format (CDF) allow context-dependent attackers to execute arbitrary code, as demonstrated using (1) an array index error in the ReadAEDRList64 function, and other errors in the (2) SearchForRecord_r_64, ...
15 years ago
CVE-2014-2850 - The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary commands via shell metacharacters in the address parameter. ...
10 years ago
CVE-2015-2850 - Cross-site scripting (XSS) vulnerability in index-login.ant in the ANTlabs InnGate firmware on IG 3100, InnGate 3.01 E, InnGate 3.10 E, InnGate 3.10 M, SG 4, and SSG 4 devices allows remote attackers to inject arbitrary web script or HTML via the msg ...
9 years ago
CVE-2016-2850 - Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct downgrade attacks via unspecified vectors. ...
7 years ago
CVE-2006-2850 - Cross-site scripting (XSS) vulnerability in recentchanges.php in PHP Labware LabWiki 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the help parameter. ...
7 years ago
CVE-2008-2850 - SQL injection vulnerability in the TrailScout module 5.x before 5.x-1.4 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified cookies, related to improper use of the Drupal database API. ...
7 years ago
CVE-2010-2850 - Directory traversal vulnerability in productionnu2/fileuploader.php in nuBuilder 10.04.20, and possibly other versions before 10.07.12, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the dir parameter. ...
7 years ago
CVE-2012-2850 - Multiple unspecified vulnerabilities in the PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allow remote attackers to have an unknown impact via a crafted document. ...
7 years ago
CVE-2018-2850 - Vulnerability in the Oracle Hospitality Cruise Fleet Management System component of Oracle Hospitality Applications (subcomponent: Fleet Management System Suite). The supported version that is affected is 9.x. Easily exploitable vulnerability allows ...
5 years ago
CVE-2020-2850 - Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with ...
4 years ago
CVE-2011-2850 - Google Chrome before 14.0.835.163 does not properly handle Khmer characters, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. ...
4 years ago
CVE-2019-2850 - Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with ...
3 years ago
CVE-2017-2850 - In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary characters in the pureftpd.passwd file during a username change, which in ...
2 years ago
CVE-2013-2850 - Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters.c in the iSCSI target subsystem in the Linux kernel through 3.9.4 allows remote attackers to cause a denial of service (memory ...
1 year ago
CVE-2023-2850 - NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user information to be extracted by attacker. ...
1 year ago
CVE-2024-2850 - A vulnerability was found in Tenda AC15 15.03.05.18 and classified as critical. Affected by this issue is the function saveParentControlInfo of the file /goform/saveParentControlInfo. The manipulation of the argument urls leads to stack-based buffer ...
7 months ago
CVE-2013-6078 - The default configuration of EMC RSA BSAFE Toolkits and RSA Data Protection Manager (DPM) 20130918 uses the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm, which makes it easier for context-dependent attackers to ...
10 years ago
CVE-2016-0012 - Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Visio 2013 SP1, ...
6 years ago
CVE-2011-1892 - Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management ...
6 years ago
CVE-2015-0085 - Use-after-free vulnerability in Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 Gold and SP1, Word 2013 Gold and SP1, Office 2013 RT Gold ...
6 years ago
CVE-2007-4246 - Unspecified vulnerability, possibly a buffer overflow, in Justsystem Ichitaro 2007 and earlier allows remote attackers to execute arbitrary code via a modified document, as actively exploited in August 2007 by malware such as Tarodrop.D (Tarodrop.Q), ...
7 years ago

Latest Cyber News


Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)