V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2010-2807
DEB
MediumConfirmedExploit available

FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote attackers to cause a denial of service …

CVSS
5.8
Medium
EPSS
0.04
p89
Published
2010-01-01
Updated
2010-01-01
Description

FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.

Tags · CWE
CWE-681
Affected products
Freetype < 2.4.2
CVSS vector
AV:N/AC:M/Au:N/C:N/I:P/A:P
Timeline
2010-01-01
Published
2010-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.042 · p89
Known exploited (KEV)
No
Known exploits — Сканер-ВС
14538
exploitdb · https://www.exploit-db.com/exploits/14538
Enterprise
14727
exploitdb · https://www.exploit-db.com/exploits/14727
Enterprise
Affected products
ProductVendorStatus
freetypeTracked
freetypeTracked
freetype*Tracked
iphone_os*Tracked
mac_os_x*Tracked
tvos*Tracked
ubuntu_linux*Tracked
Source databases
DEB
CVE
UBU
Related vulnerabilities