CVE-2006-5821
Last modified
CVE-2006-5821 is a vulnerability of currently unknown severity. Heap-based buffer overflow in the IMA_SECURE_DecryptData1 function in ImaSystem.dll for Citrix MetaFrame XP 1.0 and 2.0, and Presentation Server 3.0 and 4.0, allows remote attackers to execute arbitrary code via requests to the Independent Management Architecture (IMA) service (ImaSrv.exe) with invalid size values that trigger the overflow during decryption.. EPSS estimates a 5.19% chance of exploitation in the next 30 days.
Description
Heap-based buffer overflow in the IMA_SECURE_DecryptData1 function in ImaSystem.dll for Citrix MetaFrame XP 1.0 and 2.0, and Presentation Server 3.0 and 4.0, allows remote attackers to execute arbitrary code via requests to the Independent Management Architecture (IMA) service (ImaSrv.exe) with invalid size values that trigger the overflow during decryption.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Citrix | Metaframe | 1.0 |
| Citrix | Metaframe | 3.0 |
| Citrix | Metaframe Presentation Server | 4.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-5821?
How severe is CVE-2006-5821?
How do I fix CVE-2006-5821?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-5815Stack-based buffer overflow in the sreplace function in ProF…
- CVE-2006-5816Multiple PHP remote file inclusion vulnerabilities in Dmitry…
- CVE-2006-5817prl_dhcpd in Parallels Desktop for Mac Build 1940 uses insec…
- CVE-2006-5818Multiple buffer overflows in tunekrnl in IBM Lotus Domino 6.…
- CVE-2006-5819Verity Ultraseek before 5.7 allows remote attackers to use t…
- CVE-2006-5820The LinkSBIcons method in the SuperBuddy ActiveX control (Sb…
- CVE-2006-5822Stack-based buffer overflow in the NetBackup bpcd daemon (bp…
- CVE-2006-5823The zlib_inflate function in Linux kernel 2.6.x allows local…
- CVE-2006-5824Integer overflow in the ffs_rdextattr function in FreeBSD 6.…
- CVE-2006-5825Cross-site scripting (XSS) vulnerability in index.php in Kay…
- CVE-2006-5826Buffer overflow in Texas Imperial Software WFTPD Pro Server …
- CVE-2006-5827Multiple cross-site scripting (XSS) vulnerabilities in index…
Are you affected by CVE-2006-5821?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
