← Back

CVE-2010-2206

nvd nist
Published: Jun 30, 2010Modified: Apr 29, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

Array index error in AcroForm.api in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted GIF image in a PDF file, which bypasses a size check and triggers a heap-based buffer overflow.

Affected (40)

2 products
Acrobat
Acrobat Reader
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Version 9.0
Version 9.1.1
Version 9.1.2
Version 9.1.3
Version 9.1
Version 9.2
Version 9.3.1
Version 9.3.2
Version 9.3
Configuration B
9 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Version 9.0
Version 9.1.1
Version 9.1.2
Version 9.1.3
Version 9.1
Version 9.2
Version 9.3.1
Version 9.3.2
Version 9.3
Configuration C
12 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Version 8.0
Version 8.1.1
Version 8.1.2
Version 8.1.3
Version 8.1.4
Version 8.1.5
Version 8.1.6
Version 8.1.7
Version 8.1
Version 8.2.1
Version 8.2.2
Version 8.2
Configuration D
10 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Adobe
Version 8.0
Version 8.1.1
Version 8.1.2
Version 8.1.4
Version 8.1.5
Version 8.1.6
Version 8.1.7
Version 8.1
Version 8.2.1
Version 8.2.2
Running on/withPlatform Versions
Apple
Mac Os X
All versions
Microsoft
Windows
All versions

Related CWEs

References (14)

Timeline

No history available yet.