CVE Vulnerabilities

CVE-2010-1028

Published: Mar 19, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla3.6 (including)3.6 (including)
FirefoxMozilla3.6-a1_pre (including)3.6-a1_pre (including)
FirefoxMozilla3.6.1 (including)3.6.1 (including)
FirefoxMozilla3.7-a1_pre (including)3.7-a1_pre (including)
FirefoxMozilla3.7-alpha1 (including)3.7-alpha1 (including)
FirefoxMozilla3.7-alpha2 (including)3.7-alpha2 (including)
FirefoxUbuntudapper*
FirefoxUbuntudevel*
FirefoxUbuntuupstream*

References