CVE-2010-2883 is a critical stack-based buffer overflow vulnerability in CoolType.dll affecting Adobe Reader and Acrobat versions 9.x prior to 9.4 and 8.x prior to 8.2.5 on Windows and Mac OS X. This flaw allows remote attackers to execute arbitrary code or cause a denial of service through specially crafted PDF documents containing a long field in a Smart INdependent Glyphlets (SING) table within a TTF font. With a CVSS score of 7.3 (HIGH), the vulnerability has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, with multiple Metasploit modules and ExploitDB entries available, and has garnered significant community discussion and media coverage, indicating its widespread impact and continued relevance in threat landscapes.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0, < 8.2.5CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 9.0, < 9.4CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 8.0, < 8.2.5CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* | ||
>= 9.0, < 9.4CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.