CVE-2010-1028
published 2010-03-19CVE-2010-1028: Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3…
PriorityP344critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
8.82%
94.6th percentile
Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | calibre | < calibre 2.38.0+dfsg-1 (bookworm) | calibre 2.38.0+dfsg-1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mozilla Firefox 3.6/3.6.1/3.7 Fonts numeric error (VU#964549 / Nessus ID 45135)
vuldb·2026-05-03·CVSS 9.3
CVE-2010-1028 [CRITICAL] Mozilla Firefox 3.6/3.6.1/3.7 Fonts numeric error (VU#964549 / Nessus ID 45135)
A vulnerability classified as critical was found in Mozilla Firefox 3.6/3.6.1/3.7. This issue affects some unknown processing of the component Fonts. Executing a manipulation can lead to numeric error.
This vulnerability is handled as CVE-2010-1028. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
GHSA
GHSA-j2gp-w4x2-2gc7: Unspecified vulnerability in Mozilla Firefox 3
ghsa_unreviewed·2022-05-02·CVSS 9.3
CVE-2010-1122 [CRITICAL] CWE-119 GHSA-j2gp-w4x2-2gc7: Unspecified vulnerability in Mozilla Firefox 3
Unspecified vulnerability in Mozilla Firefox 3.5.x through 3.5.8 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly have unknown other impact via vectors that might involve compressed data, a different vulnerability than CVE-2010-1028.
GHSA
GHSA-c2mm-7gpv-8xqx: Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3
ghsa_unreviewed·2022-04-23
CVE-2010-1028 [HIGH] GHSA-c2mm-7gpv-8xqx: Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3
Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0.
OSV
CVE-2010-1028: Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3
osv·2010-03-19·CVSS 9.3
CVE-2010-1028 [CRITICAL] CVE-2010-1028: Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3
Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0.
Red Hat
firefox: unspecified code execution vulnerability (VulnDisco 9.0)
vendor_redhat·2010-02-01·CVSS 9.3
CVE-2010-1028 [CRITICAL] firefox: unspecified code execution vulnerability (VulnDisco 9.0)
firefox: unspecified code execution vulnerability (VulnDisco 9.0)
Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0.
Debian
CVE-2010-1028: calibre - Integer overflow in the decompression functionality in the Web Open Fonts Format...
vendor_debian·2010·CVSS 9.3
CVE-2010-1028 [CRITICAL] CVE-2010-1028: calibre - Integer overflow in the decompression functionality in the Web Open Fonts Format...
Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0.
Scope: local
bookworm: resolved (fixed in 2.38.0+dfsg-1)
bullseye: resolved (fixed in 2.38.0+dfsg-1)
forky: resolved (fixed in 2.38.0+dfsg-1)
sid: resolved (fixed in 2.38.0+dfsg-1)
trixie: resolved (fixed in 2.38.0+dfsg-1)
No detection rules found.
Bugzilla
calibre: vulnerable embedded copy of WOFF
bugzilla·2015-05-29·CVSS 9.3
CVE-2010-1028 [CRITICAL] calibre: vulnerable embedded copy of WOFF
calibre: vulnerable embedded copy of WOFF
Calibre contains an outdated embedded copy of Mozilla's WOFF code (in src/calibre/utils/fonts/woff/), which is known to have some security issues.
1) https://bugzilla.mozilla.org/show_bug.cgi?id=552216 (aka CVE-2010-1028)
Patch: https://hg.mozilla.org/releases/mozilla-1.9.2/rev/827a6883442f
2) https://bugzilla.mozilla.org/show_bug.cgi?id=522308
Patch: https://hg.mozilla.org/mozilla-central/rev/69eb050f2c0a
Mozilla's newest release does not contain the vulnerable code.
Originally reported at:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=787085
Discussion:
Created calibre tracking bugs for this issue:
Affects: fedora-all [bug 1226189]
---
Is there a shared library that could be used instead? (dnf search doesn't return anything usefu
Bugzilla
CVE-2010-1028 firefox: unspecified code execution vulnerability (VulnDisco 9.0)
bugzilla·2010-02-18·CVSS 9.3
CVE-2010-1028 [CRITICAL] CVE-2010-1028 firefox: unspecified code execution vulnerability (VulnDisco 9.0)
CVE-2010-1028 firefox: unspecified code execution vulnerability (VulnDisco 9.0)
A new release of VulnDisco indicates it contains a 0-day Firefox exploit against version 3.6 and possibly other versions. The vulnerability is unspecified, but is reportedly able to result in the execution of arbitrary code with the privileges of the user running Firefox.
There is no further information on this flaw currently available.
References:
https://forum.immunityinc.com/board/thread/1161/vulndisco-9-0/
http://secunia.com/advisories/38608/
Discussion:
This flaw only affected 3.6, and is fixed in 3.6.2. I'm closing this bug.
http://blog.mozilla.com/security/2010/02/22/secunia-advisory-sa38608/http://blog.mozilla.com/security/2010/03/18/update-on-secunia-advisory-sa38608/http://blog.psi2.de/en/2010/02/20/going-commercial-with-firefox-vulnerabilities/http://secunia.com/advisories/38608http://secunia.com/community/forum/thread/show/3592http://www.h-online.com/security/news/item/Zero-day-exploit-for-Firefox-3-6-936124.htmlhttp://www.kb.cert.org/vuls/id/964549http://www.mozilla.org/security/announce/2010/mfsa2010-08.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=552216https://forum.immunityinc.com/board/thread/1161/vulndisco-9-0/https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7969http://blog.mozilla.com/security/2010/02/22/secunia-advisory-sa38608/http://blog.mozilla.com/security/2010/03/18/update-on-secunia-advisory-sa38608/http://blog.psi2.de/en/2010/02/20/going-commercial-with-firefox-vulnerabilities/http://secunia.com/advisories/38608http://secunia.com/community/forum/thread/show/3592http://www.h-online.com/security/news/item/Zero-day-exploit-for-Firefox-3-6-936124.htmlhttp://www.kb.cert.org/vuls/id/964549http://www.mozilla.org/security/announce/2010/mfsa2010-08.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=552216https://forum.immunityinc.com/board/thread/1161/vulndisco-9-0/https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7969
2010-03-19
Published