peter bassill · operator
$ cve CVE-2010-2883 JSON

CVE-2010-2883 KEV EXPLOIT

7.3
HIGH · CVSS 3.1 · EPSS 81.4% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-22.

Description

Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information.

Scoring

CVSS7.3 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS81.38% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-787
On CISA KEVyes — remediate by 2022-06-22
Public exploityes
Published2010-09-09
Last modified2026-06-16

CISA KEV

NameAdobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability
Added2022-06-08
Due2022-06-22
Vendor / productAdobe / Acrobat and Reader
Ransomware usenone reported

Affected (4)

VendorProduct
adobeacrobat
adobeacrobat reader
applemacos
microsoftwindows

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD