CVE-2010-2208
published 2010-06-30CVE-2010-2208: Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, dereference a heap object after this object's deletion, which allows…
PriorityP345critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.17%
89.7th percentile
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, dereference a heap object after this object's deletion, which allows attackers to execute arbitrary code via unspecified vectors.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2f8f-mr6r-cvh9: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-14
CVE-2010-2208 [HIGH] CWE-94 GHSA-2f8f-mr6r-cvh9: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, dereference a heap object after this object's deletion, which allows attackers to execute arbitrary code via unspecified vectors.
Red Hat
acroread: multiple code execution flaws (APSB10-15)
vendor_redhat·2010-06-29·CVSS 9.3
CVE-2010-2208 [CRITICAL] acroread: multiple code execution flaws (APSB10-15)
acroread: multiple code execution flaws (APSB10-15)
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, dereference a heap object after this object's deletion, which allows attackers to execute arbitrary code via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-2595 libtiff: Array index error due improper handling of invalid ReferenceBlackWhite values
bugzilla·2010-07-02·CVSS 4.3
CVE-2010-2595 [MEDIUM] CVE-2010-2595 libtiff: Array index error due improper handling of invalid ReferenceBlackWhite values
CVE-2010-2595 libtiff: Array index error due improper handling of invalid ReferenceBlackWhite values
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-2595 to
the following vulnerability:
The TIFFYCbCrtoRGB function in LibTIFF 3.9.0 and 3.9.2, as used in
ImageMagick, does not properly handle invalid ReferenceBlackWhite
values, which allows remote attackers to cause a denial of service
(application crash) via a crafted TIFF image that triggers an array
index error, related to "downsampled OJPEG input."
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2595
[2] http://bugzilla.maptools.org/show_bug.cgi?id=2208
[3] https://bugzilla.redhat.com/show_bug.cgi?id=583081
Discussion:
This issue did NOT affect the version of the libtiff package,
as shipped
Bugzilla
acroread: multiple code execution flaws (APSB10-15)
bugzilla·2010-06-29·CVSS 9.3
[CRITICAL] acroread: multiple code execution flaws (APSB10-15)
acroread: multiple code execution flaws (APSB10-15)
Today, 2010-06-29, Adobe is planning to release an update
for Adobe Reader of version v9.3.2 and Adobe Acrobat of
version 9.3.2 (new version for both products is v9.3.3),
to address multiple security issues allowing code execution,
whose description is detailed in the Adobe Security Bulletin
APSB10-15:
[1] http://www.adobe.com/support/security/bulletins/apsb10-15.html
* This update resolves a memory corruption vulnerability that could
lead to code execution (CVE-2010-1297). Note: There are reports that
this issue is being actively exploited in the wild.
Red Hat is tracking this memory corruption vulnerability via a
dedicated Red Hat Bugzilla entry, which is reachable at:
[2] https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-1297
http://www.adobe.com/support/security/bulletins/apsb10-15.htmlhttp://www.securityfocus.com/bid/41244http://www.securitytracker.com/id?1024159http://www.vupen.com/english/advisories/2010/1636https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7188http://www.adobe.com/support/security/bulletins/apsb10-15.htmlhttp://www.securityfocus.com/bid/41244http://www.securitytracker.com/id?1024159http://www.vupen.com/english/advisories/2010/1636https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7188
2010-06-30
Published