CVE-2007-4013
Multiple unspecified vulnerabilities in (1) Net6Helper.DLL (aka Net6Launcher Class) 4.5.2 and earlier, (2) npCtxCAO.dll (aka Citrix Endpoint Analysis Client) in a Firefox plugin directory, and (3) a second npCtxCAO.dll (aka CCAOControl Object) before…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple unspecified vulnerabilities in (1) Net6Helper.DLL (aka Net6Launcher Class) 4.5.2 and earlier, (2) npCtxCAO.dll (aka Citrix Endpoint Analysis Client) in a Firefox plugin directory, and (3) a second npCtxCAO.dll (aka CCAOControl Object) before 4.5.0.0 in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 have unknown impact and attack vectors, possibly related to buffer overflows. NOTE: vector 3 might overlap CVE-2007-3679.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 4.23% probability · 90th percentile
- CISA KEV
- Not listed
- Affected
- citrix/access gateway · citrix/endpoint analysis client · mozilla/firefox
- Source
- cve@mitre.org
References
- http://osvdb.org/37842
- http://osvdb.org/37843
- http://osvdb.org/37844
- http://secunia.com/advisories/26143Patch, Vendor Advisory
- http://support.citrix.com/article/CTX113815Patch
- http://support.citrix.com/article/CTX114028Patch
- http://www.securityfocus.com/bid/24975Patch
- http://www.vupen.com/english/advisories/2007/2583
- http://osvdb.org/37842
- http://osvdb.org/37843
- http://osvdb.org/37844
- http://secunia.com/advisories/26143Patch, Vendor Advisory
- http://support.citrix.com/article/CTX113815Patch
- http://support.citrix.com/article/CTX114028Patch
- http://www.securityfocus.com/bid/24975Patch
- http://www.vupen.com/english/advisories/2007/2583
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.