CVE Vulnerabilities

CVE-2010-1028

Published: Mar 19, 2010 | Modified: Sep 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla 3.6 3.6
Firefox Mozilla 3.6 3.6
Firefox Mozilla 3.6.1 3.6.1
Firefox Mozilla 3.7 3.7
Firefox Mozilla 3.7 3.7
Firefox Mozilla 3.7 3.7

References