CVE-2010-1028
Published Mar 19, 2010
Last updated 7 years ago
Overview
- Description
- Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-189
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:mozilla:firefox:3.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F3782354-7EB7-49D2-B240-1871F6CB84C7" }, { "criteria": "cpe:2.3:a:mozilla:firefox:3.6:a1_pre:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C100B62E-9199-4983-AFC2-EBC55AF230BE" }, { "criteria": "cpe:2.3:a:mozilla:firefox:3.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "39A968C1-8F61-4A26-A098-84F9A4DD5D3B" }, { "criteria": "cpe:2.3:a:mozilla:firefox:3.7:a1_pre:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4C5C2EED-CA12-416C-8695-18DD215B0351" }, { "criteria": "cpe:2.3:a:mozilla:firefox:3.7:alpha1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6998918E-EC54-4C07-9CB4-D88FF2676651" }, { "criteria": "cpe:2.3:a:mozilla:firefox:3.7:alpha2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E2FD6B2C-9295-48F0-ADE8-9F4A2684ABD9" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "3852BB02-47A1-40B3-8E32-8D8891A53114" }, { "criteria": "cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CE477A73-4EE4-41E9-8694-5A3D5DC88656" } ], "operator": "OR" } ], "operator": "AND" } ]