CVE-2010-1028

Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
mozillafirefox
3.6
mozillafirefox
3.6:a1_pre
mozillafirefox
3.6.1
mozillafirefox
3.7:a1_pre
mozillafirefox
3.7:alpha1
mozillafirefox
3.7:alpha2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
calibre
bullseye
5.12.0+dfsg-1+deb11u2
fixed
jessie
no-dsa
wheezy
not-affected
bullseye (security)
5.12.0+dfsg-1+deb11u3
fixed
bookworm
6.13.0+repack-2+deb12u4
fixed
sid
7.20.0+ds-1
fixed
trixie
7.20.0+ds-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
karmic
dne
jaunty
dne
intrepid
dne
hardy
not-affected
dapper
ignored
Common Weakness Enumeration