Lucene search

K
cve[email protected]CVE-2010-2740
HistoryOct 13, 2010 - 7:00 p.m.

CVE-2010-2740

2010-10-1319:00:36
CWE-264
web.nvd.nist.gov
24
microsoft
windows
xp
otf
font
parsing
vulnerability
nvd
cve-2010-2740

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.3 Medium

AI Score

Confidence

Low

0.377 Low

EPSS

Percentile

97.2%

The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly perform memory allocation during font parsing, which allows local users to gain privileges via a crafted application, aka β€œOpenType Font Parsing Vulnerability.”

Affected configurations

NVD
Node
microsoftwindows_2003_serversp2
OR
microsoftwindows_server_2003sp2
OR
microsoftwindows_xpsp3
OR
microsoftwindows_xpMatch-sp2x64

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.3 Medium

AI Score

Confidence

Low

0.377 Low

EPSS

Percentile

97.2%