Vulnerability Intelligence Report
Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability
CVE-2010-2883
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
7.3
HIGH
Exploitability:1.4
Impact Score:5.9
EPSS Probability:82.48%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-787 ↗CWE-787 Out-of-bounds Write
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| adobe | acrobat | all |
| apple | macos | all |
| microsoft | windows | all |
| adobe | acrobat_reader | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Adobe Systems Incorporated · Vendor · USA |
| Reserved | 2010-07-27T00:00:00 |
| Published | 2010-09-09T21:00:00 |
| Patch Date | 2010-09-08 |
| Last Updated | 2025-10-22T00:05:51 |
Community Chatter & Buzz