CVE-2010-2210
published 2010-06-30CVE-2010-2210: Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service…
PriorityP343critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.27%
90.0th percentile
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2211, and CVE-2010-2212.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qwcx-g9pf-v9j5: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2010-2207 [CRITICAL] CWE-119 GHSA-qwcx-g9pf-v9j5: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2209, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.
GHSA
GHSA-fv9q-w2fc-m6jg: Buffer overflow in Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2010-2212 [CRITICAL] CWE-119 GHSA-fv9q-w2fc-m6jg: Buffer overflow in Adobe Reader and Acrobat 9
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a PDF file containing Flash content with a crafted #1023 (3FFh) tag, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, and CVE-2010-2211.
GHSA
GHSA-w5cf-825f-4cf6: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2010-2209 [CRITICAL] CWE-119 GHSA-w5cf-825f-4cf6: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.
GHSA
GHSA-2gfx-wjv6-pqp4: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2010-2202 [CRITICAL] CWE-119 GHSA-2gfx-wjv6-pqp4: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.
GHSA
GHSA-jgwh-gf9q-8hjj: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2010-2210 [CRITICAL] CWE-119 GHSA-jgwh-gf9q-8hjj: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2211, and CVE-2010-2212.
GHSA
GHSA-4gj4-pg9r-v8v2: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2010-2211 [CRITICAL] CWE-119 GHSA-4gj4-pg9r-v8v2: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, and CVE-2010-2212.
GHSA
GHSA-rf45-9q7g-m28g: Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-02·CVSS 9.3
CVE-2010-1295 [CRITICAL] CWE-119 GHSA-rf45-9q7g-m28g: Adobe Reader and Acrobat 9
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.
Red Hat
acroread: multiple code execution flaws (APSB10-15)
vendor_redhat·2010-06-29·CVSS 9.3
CVE-2010-2209 [CRITICAL] acroread: multiple code execution flaws (APSB10-15)
acroread: multiple code execution flaws (APSB10-15)
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.
Red Hat
acroread: multiple code execution flaws (APSB10-15)
vendor_redhat·2010-06-29·CVSS 9.3
CVE-2010-2211 [CRITICAL] acroread: multiple code execution flaws (APSB10-15)
acroread: multiple code execution flaws (APSB10-15)
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, and CVE-2010-2212.
Red Hat
acroread: multiple code execution flaws (APSB10-15)
vendor_redhat·2010-06-29·CVSS 9.3
CVE-2010-2210 [CRITICAL] acroread: multiple code execution flaws (APSB10-15)
acroread: multiple code execution flaws (APSB10-15)
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2211, and CVE-2010-2212.
Red Hat
acroread: multiple code execution flaws (APSB10-15)
vendor_redhat·2010-06-29·CVSS 9.3
CVE-2010-2202 [CRITICAL] acroread: multiple code execution flaws (APSB10-15)
acroread: multiple code execution flaws (APSB10-15)
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.
Red Hat
acroread: multiple code execution flaws (APSB10-15)
vendor_redhat·2010-06-29·CVSS 9.3
CVE-2010-2212 [CRITICAL] acroread: multiple code execution flaws (APSB10-15)
acroread: multiple code execution flaws (APSB10-15)
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a PDF file containing Flash content with a crafted #1023 (3FFh) tag, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, and CVE-2010-2211.
Red Hat
acroread: multiple code execution flaws (APSB10-15)
vendor_redhat·2010-06-29·CVSS 9.3
CVE-2010-2207 [CRITICAL] acroread: multiple code execution flaws (APSB10-15)
acroread: multiple code execution flaws (APSB10-15)
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2209, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.
Red Hat
acroread: multiple code execution flaws (APSB10-15)
vendor_redhat·2010-06-29·CVSS 9.3
CVE-2010-1295 [CRITICAL] acroread: multiple code execution flaws (APSB10-15)
acroread: multiple code execution flaws (APSB10-15)
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-2630 libtiff: crash on out-of-order codec-specific tags
bugzilla·2010-07-06·CVSS 4.3
CVE-2010-2630 [MEDIUM] CVE-2010-2630 libtiff: crash on out-of-order codec-specific tags
CVE-2010-2630 libtiff: crash on out-of-order codec-specific tags
The TIFFReadDirectory function in LibTIFF 3.9.0 does not properly
validate the data types of codec-specific tags that have an
out-of-order position in a TIFF file, which allows remote attackers to
cause a denial of service (application crash) via a crafted file, a
different vulnerability than CVE-2010-2481.
References:
https://bugzilla.redhat.com/show_bug.cgi?id=554371
http://bugzilla.maptools.org/show_bug.cgi?id=2210
Discussion:
This particular symptom of unknown / out-of-order tag handling issues did not affect current libtiff packages in Red Hat Enterprise Linux 3, 4 and 5 due to previously applied patch (libtiff-*-ormandy.patch). Future libtiff updates will improve that patch to use approach from patch submitted in th
Bugzilla
CVE-2010-2631 libtiff: unknown tag handling assertion failure
bugzilla·2010-07-06·CVSS 4.3
CVE-2010-2631 [MEDIUM] CVE-2010-2631 libtiff: unknown tag handling assertion failure
CVE-2010-2631 libtiff: unknown tag handling assertion failure
LibTIFF 3.9.0 ignores tags in certain situations during the first
stage of TIFF file processing and does not properly handle this during
the second stage, which allows remote attackers to cause a denial of
service (application crash) via a crafted file, a different
vulnerability than CVE-2010-2481.
References:
http://bugzilla.maptools.org/show_bug.cgi?id=2210
Discussion:
It seems this CVE was assigned based on the following comment in the upstream bug report:
http://bugzilla.maptools.org/show_bug.cgi?id=2210#c3
It was added in response to the Red Hat bug:
https://bugzilla.redhat.com/show_bug.cgi?id=603699
Upstream bug report #2210 contains patch to address issues related to handling of unknown tags, which could lead to var
Bugzilla
CVE-2010-2481 libtiff: TIFFExtractData out-of-bounds read crash
bugzilla·2010-07-06·CVSS 4.3
CVE-2010-2481 [MEDIUM] CVE-2010-2481 libtiff: TIFFExtractData out-of-bounds read crash
CVE-2010-2481 libtiff: TIFFExtractData out-of-bounds read crash
The TIFFExtractData macro in LibTIFF before 3.9.4 does not properly
handle unknown tag types in TIFF directory entries, which allows
remote attackers to cause a denial of service (out-of-bounds read and
application crash) via a crafted TIFF file.
References:
http://thread.gmane.org/gmane.comp.security.oss.general/3075/focus=3097
http://bugzilla.maptools.org/show_bug.cgi?id=2210
Discussion:
According to Dan Rosenberg's report, this was originally reported to iDefense. Dan did not publish too much details about this issue, as it's addressed by Tom's patch from upstream bug report #2210.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2010:0519 https:
Bugzilla
acroread: multiple code execution flaws (APSB10-15)
bugzilla·2010-06-29·CVSS 9.3
[CRITICAL] acroread: multiple code execution flaws (APSB10-15)
acroread: multiple code execution flaws (APSB10-15)
Today, 2010-06-29, Adobe is planning to release an update
for Adobe Reader of version v9.3.2 and Adobe Acrobat of
version 9.3.2 (new version for both products is v9.3.3),
to address multiple security issues allowing code execution,
whose description is detailed in the Adobe Security Bulletin
APSB10-15:
[1] http://www.adobe.com/support/security/bulletins/apsb10-15.html
* This update resolves a memory corruption vulnerability that could
lead to code execution (CVE-2010-1297). Note: There are reports that
this issue is being actively exploited in the wild.
Red Hat is tracking this memory corruption vulnerability via a
dedicated Red Hat Bugzilla entry, which is reachable at:
[2] https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-1297
http://www.adobe.com/support/security/bulletins/apsb10-15.htmlhttp://www.securityfocus.com/bid/41242http://www.securitytracker.com/id?1024159http://www.vupen.com/english/advisories/2010/1636https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6929http://www.adobe.com/support/security/bulletins/apsb10-15.htmlhttp://www.securityfocus.com/bid/41242http://www.securitytracker.com/id?1024159http://www.vupen.com/english/advisories/2010/1636https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6929
2010-06-30
Published