CVE-2010-2883
גבוהה 7.3 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information.
מדדים
- CVSS 3.1
-
7.3 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 82% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-787
מוצרים מושפעים
adobe: acrobat; apple: macos; microsoft: windows; adobe: acrobat reader
קישורים
- http://secunia.com/advisories/41340 Broken LinkVendor Advisory
- http://secunia.com/advisories/43025 Broken LinkVendor Advisory
- http://www.adobe.com/support/security/advisories/apsa10-02.html Vendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb10-21.html Vendor Advisory
- http://www.vupen.com/english/advisories/2010/2331 Broken LinkVendor Advisory
- http://www.vupen.com/english/advisories/2011/0191 Broken LinkVendor Advisory
- http://www.vupen.com/english/advisories/2011/0344 Broken LinkVendor Advisory
- http://secunia.com/advisories/41340 Broken LinkVendor Advisory
- http://secunia.com/advisories/43025 Broken LinkVendor Advisory
- http://www.adobe.com/support/security/advisories/apsa10-02.html Vendor Advisory