Vulnerability Report

CVE-2010-3704

Title: Glyphandcog Xpdfreader RCE

Memory Corruption

Proof Of Concept

No public PoC currently indexed for CVE-2010-3704.

CWE Category CWE-20
Published Date Nov 05, 2010
Modified Date Jun 16, 2026
Exploit Status Not Found
Score 6.8 CVSS v2.0
Exploit Probability (EPSS)
3.60%

Vulnerability Summary

CVE-2010-3704: The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a crafted PostScript Type1 font that contains a negative array index, which bypasses input validation and triggers memory corruption.

Impacted Vendors

Reference Links

ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl5.patch http://cgit.freedesktop.org/poppler/poppler/commit/?id=39d140bfc0b8239bdd96d6a55842034ae5c05473 http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050268.html http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050285.html http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050390.html http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049392.html http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049523.html http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049545.html http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00006.html http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html http://rhn.redhat.com/errata/RHSA-2012-1201.html http://secunia.com/advisories/42141 http://secunia.com/advisories/42357 http://secunia.com/advisories/42397 http://secunia.com/advisories/42691 http://secunia.com/advisories/43079 http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.571720 http://www.debian.org/security/2010/dsa-2119 http://www.debian.org/security/2010/dsa-2135 http://www.mandriva.com/security/advisories?name=MDVSA-2010:228 http://www.mandriva.com/security/advisories?name=MDVSA-2010:229 http://www.mandriva.com/security/advisories?name=MDVSA-2010:230 http://www.mandriva.com/security/advisories?name=MDVSA-2010:231 http://www.mandriva.com/security/advisories?name=MDVSA-2012:144 http://www.openoffice.org/security/cves/CVE-2010-3702_CVE-2010-3704.html http://www.openwall.com/lists/oss-security/2010/10/04/6 http://www.redhat.com/support/errata/RHSA-2010-0749.html http://www.redhat.com/support/errata/RHSA-2010-0751.html http://www.redhat.com/support/errata/RHSA-2010-0752.html http://www.redhat.com/support/errata/RHSA-2010-0753.html http://www.redhat.com/support/errata/RHSA-2010-0859.html http://www.securityfocus.com/bid/43841 http://www.ubuntu.com/usn/USN-1005-1 http://www.vupen.com/english/advisories/2010/2897 http://www.vupen.com/english/advisories/2010/3097 http://www.vupen.com/english/advisories/2011/0230 https://bugzilla.redhat.com/show_bug.cgi?id=638960 ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl5.patch http://cgit.freedesktop.org/poppler/poppler/commit/?id=39d140bfc0b8239bdd96d6a55842034ae5c05473 http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050268.html http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050285.html http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050390.html http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049392.html http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049523.html http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049545.html http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00006.html http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html http://rhn.redhat.com/errata/RHSA-2012-1201.html http://secunia.com/advisories/42141 http://secunia.com/advisories/42357 http://secunia.com/advisories/42397 http://secunia.com/advisories/42691 http://secunia.com/advisories/43079 http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.571720 http://www.debian.org/security/2010/dsa-2119 http://www.debian.org/security/2010/dsa-2135 http://www.mandriva.com/security/advisories?name=MDVSA-2010:228 http://www.mandriva.com/security/advisories?name=MDVSA-2010:229 http://www.mandriva.com/security/advisories?name=MDVSA-2010:230 http://www.mandriva.com/security/advisories?name=MDVSA-2010:231 http://www.mandriva.com/security/advisories?name=MDVSA-2012:144 http://www.openoffice.org/security/cves/CVE-2010-3702_CVE-2010-3704.html http://www.openwall.com/lists/oss-security/2010/10/04/6 http://www.redhat.com/support/errata/RHSA-2010-0749.html http://www.redhat.com/support/errata/RHSA-2010-0751.html http://www.redhat.com/support/errata/RHSA-2010-0752.html http://www.redhat.com/support/errata/RHSA-2010-0753.html http://www.redhat.com/support/errata/RHSA-2010-0859.html http://www.securityfocus.com/bid/43841 http://www.ubuntu.com/usn/USN-1005-1 http://www.vupen.com/english/advisories/2010/2897 http://www.vupen.com/english/advisories/2010/3097 http://www.vupen.com/english/advisories/2011/0230 https://bugzilla.redhat.com/show_bug.cgi?id=638960
CVSS v2.0
Source Entity [email protected]
Severity MEDIUM
6.8
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:N/AC:M/Au:N/C:P/I:P/A:P

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2010-3704 Exploits & PoCs (Proof Of Concept)

No public PoCs found in our database for this CVE.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector N/A
Complexity N/A
Privileges N/A
Interaction NONE
CVSS Vector String AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected Stack

No specific products linked.