VDB
CVE-2010-3311
CVE-2010-3311
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Compact Font Format (CFF) font file that triggers a heap-based buffer overflow, related to an "input stream position error" issue, a different vulnerability than CVE-2010-1797.
EPSS 6.74% · 93.7th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
6.74%
93.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| freetype | freetype | 0, 2.0.6, 2.0.9 |
Timeline
- Jan 7, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
- Nov 1, 2023 EPSS Score
References
- MDVSA-2010:201 vendor-advisory
- RHSA-2010:0736 vendor-advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html technical
- http://www.securityfocus.com/bid/43700 technical
- http://secunia.com/advisories/48951 technical
- http://www.debian.org/security/2010/dsa-2116 technical
- http://www.redhat.com/support/errata/RHSA-2010-0864.html technical
- https://bugzilla.redhat.com/show_bug.cgi?id=623625 technical
- https://rhn.redhat.com/errata/RHSA-2010-0737.html technical
- https://nvd.nist.gov/vuln/detail/CVE-2010-3311 advisory
- https://access.redhat.com/errata/RHSA-2010:0736 url
- https://access.redhat.com/errata/RHSA-2010:0737 url
- https://access.redhat.com/errata/RHSA-2010:0864 url
- https://access.redhat.com/security/cve/CVE-2010-3311 url
- http://www.ubuntu.com/usn/USN-1013-1 url