← Vulnerability feed

Vulnerability record · CVE-2006-6334 · published 8 December 2006

CVE-2006-6334: Citrix presentation server client vulnerability

Citrix · Presentation Server Client

Heap-based buffer overflow in the SendChannelData function in wfica.ocx in Citrix Presentation Server Client before 9.230 for Windows allows remote malicious web sites to execute arbitrary code via a DataSize parameter that is less than the length of the Data buffer.

6.8 CVSS 2.0 Medium EPSS 35% · top 1.6%
6.8CVSS 2.0 base score
35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
26References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in the SendChannelData function in wfica.ocx in Citrix Presentation Server Client before 9.230 for Windows allows remote malicious web sites to execute arbitrary code via a DataSize parameter that is less than the length of the Data buffer.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://fortconsult.net/files/fortconsult.dk/citrix_advisory_dec2006.pdf
http://secunia.com/advisories/23246 Vendor Advisory
http://securityreason.com/securityalert/1995
http://securitytracker.com/id?1017343 PatchVendor Advisory
http://support.citrix.com/article/CTX111827 ExploitPatchVendor Advisory
http://www.citrix.com/English/SS/downloads/downloads.asp?dID=2755 PatchVendor Advisory
http://www.kb.cert.org/vuls/id/210969 US Government Resource
http://www.securityfocus.com/archive/1/453760/100/0/threaded
http://www.securityfocus.com/bid/21458 Vendor Advisory
http://www.tippingpoint.com/security/advisories/TSRT-06-15.html ExploitPatchVendor Advisory
http://www.vupen.com/english/advisories/2006/4865
https://exchange.xforce.ibmcloud.com/vulnerabilities/30740
https://www.exploit-db.com/exploits/5106
http://fortconsult.net/files/fortconsult.dk/citrix_advisory_dec2006.pdf
http://secunia.com/advisories/23246 Vendor Advisory
http://securityreason.com/securityalert/1995
http://securitytracker.com/id?1017343 PatchVendor Advisory
http://support.citrix.com/article/CTX111827 ExploitPatchVendor Advisory
http://www.citrix.com/English/SS/downloads/downloads.asp?dID=2755 PatchVendor Advisory
http://www.kb.cert.org/vuls/id/210969 US Government Resource
http://www.securityfocus.com/archive/1/453760/100/0/threaded
http://www.securityfocus.com/bid/21458 Vendor Advisory
http://www.tippingpoint.com/security/advisories/TSRT-06-15.html ExploitPatchVendor Advisory
http://www.vupen.com/english/advisories/2006/4865
https://exchange.xforce.ibmcloud.com/vulnerabilities/30740
https://www.exploit-db.com/exploits/5106

Track CVE-2006-6334 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2006-6334), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.