CVE-2009-3936
Severity CVSS v4.0:
Pending analysis
Type:
CWE-310
Cryptographic Issues
Publication date:
13/11/2009
Last modified:
09/04/2025
Description
Unspecified vulnerability in Citrix Online Plug-in for Windows 11.0.x before 11.0.150 and 11.x before 11.2, Online Plug-in for Mac before 11.0, Receiver for iPhone before 1.0.3, and ICA Java, Mac, UNIX, and Windows Clients for XenApp and XenDesktop allows remote attackers to impersonate the SSL/TLS server and bypass authentication via a crafted certificate, a different vulnerability than CVE-2009-3555.
Impact
Base Score 2.0
5.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:citrix:online_plug-in_for_mac:*:*:*:*:*:*:*:* | 10.0 (including) | |
| cpe:2.3:a:citrix:online_plug-in_for_windows:*:*:*:*:*:*:*:* | 11.2 (including) | |
| cpe:2.3:a:citrix:online_plug-in_for_windows:11.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:citrix:online_plug-in_for_windows:11.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:citrix:receiver_for_iphone:*:*:*:*:*:*:*:* | 1.0 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/37319
- http://support.citrix.com/article/CTX123248
- http://www.securityfocus.com/bid/37073
- http://www.securitytracker.com/id?1023168=
- http://www.vupen.com/english/advisories/2009/3206
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54213
- http://secunia.com/advisories/37319
- http://support.citrix.com/article/CTX123248
- http://www.securityfocus.com/bid/37073
- http://www.securitytracker.com/id?1023168=
- http://www.vupen.com/english/advisories/2009/3206
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54213



