Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2011-0033 | First vendor Publication | 2011-02-10 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The OpenType Compact Font Format (CFF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate parameter values in OpenType fonts, which allows remote attackers to execute arbitrary code via a crafted font, aka "OpenType Font Encoded Character Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0033 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-20 | Improper Input Validation |
OVAL Definitions
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2011-02-09 | Name : Vulnerability in the OpenType Compact Font Format (CFF) Driver Could Allow Re... File : nvt/secpod_ms11-007.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
70821 | Microsoft OpenType Compact Font Format (CFF) Parsing Remote Code Execution Microsoft OpenType Compact Font Format (CFF) driver contains a flaw related to the parsing of crafted OpenType fonts. This may allow a context-dependent attacker to use a crafted web page containing these fonts to execute arbitrary code. |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Microsoft Windows ATMFD Adobe font driver remote code execution attempt RuleID : 19196 - Revision : 9 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows ATMFD Adobe font driver remote code execution attempt RuleID : 18402 - Revision : 13 - Type : FILE-OTHER |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2011-02-08 | Name : The remote Windows host contains a font driver that is affected by a privileg... File : smb_nt_ms11-007.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:06:08 |
|
2024-11-28 12:24:17 |
|
2023-12-07 21:28:03 |
|
2021-05-04 12:13:44 |
|
2021-04-22 01:14:53 |
|
2020-05-23 00:27:29 |
|
2019-02-26 17:19:34 |
|
2018-10-31 00:20:09 |
|
2018-10-13 00:23:02 |
|
2017-09-19 09:24:07 |
|
2017-08-17 09:23:13 |
|
2016-08-31 12:02:29 |
|
2016-08-05 12:02:50 |
|
2016-06-28 18:28:49 |
|
2016-04-26 20:26:59 |
|
2014-02-17 10:59:16 |
|
2014-01-19 21:27:20 |
|
2013-05-10 22:51:53 |
|