VDB
CVE-2010-3311
CVE-2010-3311
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Compact Font Format (CFF) font file that triggers a heap-based buffer overflow, related to an "input stream position error" issue, a different vulnerability than CVE-2010-1797.
EPSS 5.26% · 90.2th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
5.26%
90.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| freetype | freetype | 0, 2.0.6, 2.0.9 |
Exploit Intelligence
- 43700 (circl)
- DSA-2116 (circl)
- RHSA-2010:0737 (circl)
- MDVSA-2010:201 (circl)
- USN-1013-1 (circl)
- RHSA-2010:0864 (circl)
- 48951 (circl)
- SUSE-SR:2010:019 (circl)
- https://bugzilla.redhat.com/show_bug.cgi?id=623625 (circl)
- RHSA-2010:0736 (circl)
Timeline
- Jan 7, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Aug 28, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- 43700 vdb
- DSA-2116 vendor-advisory
- RHSA-2010:0737 vendor-advisory
- MDVSA-2010:201 vendor-advisory
- USN-1013-1 vendor-advisory
- RHSA-2010:0864 vendor-advisory
- 48951 third-party-advisory
- SUSE-SR:2010:019 vendor-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=623625 url
- RHSA-2010:0736 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2010-3311 advisory
- https://access.redhat.com/errata/RHSA-2010:0736 url
- https://access.redhat.com/errata/RHSA-2010:0737 url
- https://access.redhat.com/errata/RHSA-2010:0864 url
- https://access.redhat.com/security/cve/CVE-2010-3311 url