CVE Vulnerabilities

CVE-2010-1028

Published: Mar 19, 2010 | Modified: Sep 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla 3.6 (including) 3.6 (including)
Firefox Mozilla 3.6-a1_pre (including) 3.6-a1_pre (including)
Firefox Mozilla 3.6.1 (including) 3.6.1 (including)
Firefox Mozilla 3.7-a1_pre (including) 3.7-a1_pre (including)
Firefox Mozilla 3.7-alpha1 (including) 3.7-alpha1 (including)
Firefox Mozilla 3.7-alpha2 (including) 3.7-alpha2 (including)
Firefox Ubuntu dapper *
Firefox Ubuntu devel *
Firefox Ubuntu upstream *

References