CVE-2010-4515
published 2010-12-09CVE-2010-4515: Cross-site scripting (XSS) vulnerability in Citrix Web Interface 5.0, 5.1, and 5.3 allows remote attackers to inject arbitrary web script or HTML via…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.78%
75.6th percentile
Cross-site scripting (XSS) vulnerability in Citrix Web Interface 5.0, 5.1, and 5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-6477 and CVE-2009-2454.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | web_interface | — | — |
| citrix | web_interface | — | — |
| citrix | web_interface | — | — |
| citrix | web_interface | — | — |
| citrix | xenserver | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
CVE-2010-4515: Cross-site scripting (XSS) vulnerability in Citrix Web Interface 5.0, 5.1, and 5.3 allows remote attackers to inject arbitrary web script or HTML via
vendor_citrix·2010-12-09·CVSS 4.3
CVE-2010-4515 [MEDIUM] CWE-79 CVE-2010-4515: Cross-site scripting (XSS) vulnerability in Citrix Web Interface 5.0, 5.1, and 5.3 allows remote attackers to inject arbitrary web script or HTML via
CVE-2010-4515: Cross-site scripting (XSS) vulnerability in Citrix Web Interface 5.0, 5.1, and 5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-6477 and CVE-2009-2454.
Citrix
Citrix Security Bulletin CTX127541
vendor_citrix·CVSS 4.3
CVE-2010-4515 [MEDIUM] Citrix Security Bulletin CTX127541
Citrix Security Bulletin CTX127541
CVE References: CVE-2010-4515, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
GHSA
GHSA-fpx6-72jp-cwh4: Cross-site scripting (XSS) vulnerability in Citrix Web Interface 5
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2010-4515 [MEDIUM] CWE-79 GHSA-fpx6-72jp-cwh4: Cross-site scripting (XSS) vulnerability in Citrix Web Interface 5
Cross-site scripting (XSS) vulnerability in Citrix Web Interface 5.0, 5.1, and 5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-6477 and CVE-2009-2454.
No detection rules found.
Exploit-DB
Konqueror 4.7.3 - Memory Corruption
exploitdb·2012-11-01·CVSS 9.3
CVE-2012-4515 [CRITICAL] Konqueror 4.7.3 - Memory Corruption
Konqueror 4.7.3 - Memory Corruption
---
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Nth Dimension Security Advisory (NDSA20121010)
Date: 10th October 2012
Author: Tim Brown
URL: /
Product: Konqueror 4.7.3
Vendor: KDE
Risk: Medium
Summary
The Konqueror web browser is vulnerable to a number of memory corruption
vulnerabilities.
This advisory comes in 4 related parts:
1) The Konqueror web browser is vulnerable to type confusion leading to memory
disclosure. The root cause of this is the same as CVE-2010-0046 reported by
Chris Rohlf which affected WebKit.
2) The Konqueror web browser is vulnerable to an out of bounds memory access
when accessing the canvas. In this case the vulnerability was identified whilst
playing with bug #43813 from Google's Chrome repository.
3) The Konquero
Exploit-DB
Yahoo! Messenger - 'YVerInfo.dll' ActiveX Control Buffer Overflow (Metasploit)
exploitdb·2010-05-09
CVE-2007-4515 Yahoo! Messenger - 'YVerInfo.dll' ActiveX Control Buffer Overflow (Metasploit)
Yahoo! Messenger - 'YVerInfo.dll' ActiveX Control Buffer Overflow (Metasploit)
---
##
# $Id: yahoomessenger_fvcom.rb 9262 2010-05-09 17:45:00Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Yahoo! Messenger YVerInfo.dll ActiveX Control Buffer Overflow',
'Description' => %q{
This module exploits a stack buffer overflow in the Yahoo! Messenger ActiveX
Control (YVerInfo.dll MSF_LICENSE,
'Author' => [ 'MC' ],
'Version' => '$Revision: 9262 $',
'References' =>
[
[ 'CVE', '2007-4515' ],
[ 'OSVDB', '37739' ],
[ 'BID', '25494' ],
[ 'URL', '
No writeups or analysis indexed.
http://osvdb.org/69676http://secunia.com/advisories/39514http://support.citrix.com/article/CTX127541http://www.securityfocus.com/bid/45291http://www.vupen.com/english/advisories/2010/3153http://osvdb.org/69676http://secunia.com/advisories/39514http://support.citrix.com/article/CTX127541http://www.securityfocus.com/bid/45291http://www.vupen.com/english/advisories/2010/3153
2010-12-09
Published