CVE-2010-2807 describes a vulnerability in FreeType versions prior to 2.4.2, affecting products from Apple, Canonical, and FreeType itself. This flaw stems from incorrect integer data types in bounds checking, allowing remote attackers to trigger a denial of service or potentially execute arbitrary code through a specially crafted font file. With a CVSS score of 6.8, this vulnerability has a network attack vector and medium attack complexity, leading to partial impacts on confidentiality, integrity, and availability. Despite its potential impact, there is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community or media discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4.2CPE matchmatch criteria | cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:* | ||
6.06CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:* | ||
8.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:* | ||
9.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:* | ||
9.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.