7.6

CVE-2010-2643

Integer overflow in the TFM font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RedhatEvince Version0.1
RedhatEvince Version0.2
RedhatEvince Version0.3
RedhatEvince Version0.4
RedhatEvince Version0.5
RedhatEvince Version0.6
RedhatEvince Version0.7
RedhatEvince Version0.8
RedhatEvince Version0.9
RedhatEvince Version2.19
RedhatEvince Version2.20
RedhatEvince Version2.21
RedhatEvince Version2.22
RedhatEvince Version2.23
RedhatEvince Version2.24
RedhatEvince Version2.25
RedhatEvince Version2.26
RedhatEvince Version2.27
RedhatEvince Version2.28
RedhatEvince Version2.29
RedhatEvince Version2.29.92
RedhatEvince Version2.30
RedhatEvince Version2.30.2
RedhatEvince Version2.30.3
RedhatEvince Version2.31
RedhatEvince Version2.31.1
RedhatEvince Version2.31.2
RedhatEvince Version2.31.4
RedhatEvince Version2.31.4.1
RedhatEvince Version2.31.6
RedhatEvince Version2.31.6.1
RedhatEvince Version2.31.90
RedhatEvince Version2.31.92
RedhatEvince Version2.32
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.84% 0.916
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.6 4.9 10
AV:N/AC:H/Au:N/C:C/I:C/A:C