9.3
CVSSv2

CVE-2010-1028

Published: 19/03/2010 Updated: 19/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 prior to 3.6.2 and 3.7 prior to 3.7 alpha 3 allows remote malicious users to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 3.6.1

mozilla firefox 3.6

mozilla firefox 3.7

Vendor Advisories

Debian Bug report logs - #787085 calibre: Security issues in WOFF code Package: src:calibre; Maintainer for src:calibre is Norbert Preining <norbert@preininginfo>; Reported by: Dmitry Shachnev <mitya57@debianorg> Date: Thu, 28 May 2015 12:18:06 UTC Severity: normal Tags: security Found in version calibre/2240+df ...
Mozilla Foundation Security Advisory 2010-08 WOFF heap corruption due to integer overflow Announced March 22, 2010 Reporter Evgeny Legerov Impact Critical Products Firefox Fixed in ...