CVE-2011-2882
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 56%
from disclosure to weapon41 days
Published on NVDJul 21
1st PoC+41d
metasploitJul 14
exploitation probability
56%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 allows remote attackers to execute arbitrary code via crafted HTTP header data.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/17762unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.