← All CVEs

CVE-2010-2642

high · 7.6

Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possibly other products allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.

7.6
CVSS
14.3%
EPSS (exploit prob.)
96th
EPSS percentile
2011-01-07
Published

AV:N/AC:H/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
redhatevince<= 2.32
redhatevince0.1
redhatevince0.2
redhatevince0.3
redhatevince0.4
redhatevince0.5
redhatevince0.6
redhatevince0.7
redhatevince0.8
redhatevince0.9
redhatevince2.19
redhatevince2.20
redhatevince2.21
redhatevince2.22
redhatevince2.23
redhatevince2.24
redhatevince2.25
redhatevince2.26
redhatevince2.27
redhatevince2.28
redhatevince2.29
redhatevince2.29.92
redhatevince2.30
redhatevince2.30.2
redhatevince2.30.3
redhatevince2.31
redhatevince2.31.1
redhatevince2.31.2
redhatevince2.31.4
redhatevince2.31.4.1
redhatevince2.31.6
redhatevince2.31.6.1
redhatevince2.31.90
redhatevince2.31.92
t1libt1lib5.1.2
tugtetex3.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-2642