Lucene search

K
cveMitreCVE-2010-2640
HistoryJan 07, 2011 - 7:00 p.m.

CVE-2010-2640

2011-01-0719:00:17
CWE-20
mitre
web.nvd.nist.gov
43
cve
2010
2640
array index error
pk font parser
evince
dvi-backend
denial of service
application crash

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.062

Percentile

93.6%

Array index error in the PK font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.

Affected configurations

Nvd
Node
redhatevinceRange2.32
OR
redhatevinceMatch0.1
OR
redhatevinceMatch0.2
OR
redhatevinceMatch0.3
OR
redhatevinceMatch0.4
OR
redhatevinceMatch0.5
OR
redhatevinceMatch0.6
OR
redhatevinceMatch0.7
OR
redhatevinceMatch0.8
OR
redhatevinceMatch0.9
OR
redhatevinceMatch2.19
OR
redhatevinceMatch2.20
OR
redhatevinceMatch2.21
OR
redhatevinceMatch2.22
OR
redhatevinceMatch2.23
OR
redhatevinceMatch2.24
OR
redhatevinceMatch2.25
OR
redhatevinceMatch2.26
OR
redhatevinceMatch2.27
OR
redhatevinceMatch2.28
OR
redhatevinceMatch2.29
OR
redhatevinceMatch2.29.92
OR
redhatevinceMatch2.30
OR
redhatevinceMatch2.30.2
OR
redhatevinceMatch2.30.3
OR
redhatevinceMatch2.31
OR
redhatevinceMatch2.31.1
OR
redhatevinceMatch2.31.2
OR
redhatevinceMatch2.31.4
OR
redhatevinceMatch2.31.4.1
OR
redhatevinceMatch2.31.6
OR
redhatevinceMatch2.31.6.1
OR
redhatevinceMatch2.31.90
OR
redhatevinceMatch2.31.92
VendorProductVersionCPE
redhatevince*cpe:2.3:a:redhat:evince:*:*:*:*:*:*:*:*
redhatevince0.1cpe:2.3:a:redhat:evince:0.1:*:*:*:*:*:*:*
redhatevince0.2cpe:2.3:a:redhat:evince:0.2:*:*:*:*:*:*:*
redhatevince0.3cpe:2.3:a:redhat:evince:0.3:*:*:*:*:*:*:*
redhatevince0.4cpe:2.3:a:redhat:evince:0.4:*:*:*:*:*:*:*
redhatevince0.5cpe:2.3:a:redhat:evince:0.5:*:*:*:*:*:*:*
redhatevince0.6cpe:2.3:a:redhat:evince:0.6:*:*:*:*:*:*:*
redhatevince0.7cpe:2.3:a:redhat:evince:0.7:*:*:*:*:*:*:*
redhatevince0.8cpe:2.3:a:redhat:evince:0.8:*:*:*:*:*:*:*
redhatevince0.9cpe:2.3:a:redhat:evince:0.9:*:*:*:*:*:*:*
Rows per page:
1-10 of 341

References

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.062

Percentile

93.6%