CVE-2010-3704 describes a denial-of-service and potential arbitrary code execution vulnerability in the FoFiType1::parse function of PDF parsers like xpdf, poppler, and kdegraphics. An attacker could exploit this by crafting a malicious PDF with a negative array index in a PostScript Type1 font, bypassing input validation and causing memory corruption. With a CVSS score of 6.8, this vulnerability is of medium severity, requiring user interaction (opening a malicious PDF) for exploitation, and could lead to a crash or compromise of the affected system. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.8.7CPE matchmatch criteria | cpe:2.3:a:poppler:poppler:0.8.7:*:*:*:*:*:*:* | ||
0.9.0CPE matchmatch criteria | cpe:2.3:a:poppler:poppler:0.9.0:*:*:*:*:*:*:* | ||
0.9.1CPE matchmatch criteria | cpe:2.3:a:poppler:poppler:0.9.1:*:*:*:*:*:*:* | ||
0.9.2CPE matchmatch criteria | cpe:2.3:a:poppler:poppler:0.9.2:*:*:*:*:*:*:* | ||
0.9.3CPE matchmatch criteria | cpe:2.3:a:poppler:poppler:0.9.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
xpdf: array indexing error in FoFiType1::parse()
Sep 24, 2010Security Vulnerability in OpenOffice.org's PDF Import extension resulting from 3rd party library XPDF
Security Vulnerability in OpenOffice.org's PDF Import extension resulting from 3rd party library XPDF
Security Vulnerability in OpenOffice.org's PDF Import extension resulting from 3rd party library XPDF
Security Vulnerability in OpenOffice.org's PDF Import extension resulting from 3rd party library XPDF