Ulteo's vulnerability footprint centers on its Open Virtual Desktop platform, a remote-access and application-virtualization product that serves specialized deployment contexts. The durable signal from its disclosures reflects application-layer input-handling weaknesses, notably cross-site scripting vulnerabilities arising from improper neutralization during web page generation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ulteo over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1785MEDIUM Cross-site scripting (XSS) vulnerability in Ulteo Open Virtual Desktop 1.0 allows remote attackers to inject arbitrary web script or HTML via the error parameter to header.php. NO | May 22, 2009 | 4.3 | 15 | NO | NO |
CVE-2009-1775MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Ulteo Open Virtual Desktop 1.0 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) admi | May 22, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ulteo.
Media articles that mention a CVE ID that affects a product developed by Ulteo — matched by CVE ID, not by vendor name.