CVE-2016-9678Use After Free in Citrix Provisioning Services

CWE-416Use After Free5 documents4 sources
Severity
9.8CRITICALNVD
EPSS
4.4%
top 10.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 18
Latest updateMay 17

Description

Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages8 packages

🔴Vulnerability Details

1
GHSA
GHSA-p5rw-9673-832m: Use-after-free vulnerability in Citrix Provisioning Services before 72022-05-17

💥Exploits & PoCs

1
Exploit-DB
modified eCommerce Shopsoftware 2.0.0.0 rev 9678 - Blind SQL Injection2016-04-19

📋Vendor Advisories

2
Citrix
CVE-2016-9678: Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.2017-01-18
Citrix
Citrix Security Bulletin CTX219580