CVE-2010-1797

Scores

EPSS

0.000none0.0%
0%20%40%60%80%100%

Percentile: 0.0%

CVSS

9.3critical2.0
0246810

CVSS Score: 9.3/10

All CVSS Scores

CVSS 2.0
9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Description

Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on the iPad, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted CFF opcodes in embedded fonts in a PDF document, as demonstrated by JailbreakMe. NOTE: some of these details are obtained from third party information.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debiannvdubuntu

CWEs

CWE-119

Related Vulnerabilities

Exploits

Exploit ID: 14538

Source: exploitdb

URL: https://www.exploit-db.com/exploits/14538

Exploit ID: 14727

Source: exploitdb

URL: https://www.exploit-db.com/exploits/14727

Vulnerable Software (3)

Type: Configuration

Product: freetype

Operating System: ubuntu hardy 8.04

Trait:
{  "fixed": "2.3.5-1ubuntu4.8.04.4"}

Source: ubuntu

Type: Configuration

Product: freetype

Operating System: debian

Trait:
{  "fixed": "2.4.2-1"}

Source: debian

Type: Configuration

Vendor: apple

Product: iphone_os

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:o:apple:iphone_os:1.0.0:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:o:apple:iphone_os:1.0.1:*:*:*:*:*:*:*",   ...

Source: nvd