CVE-2010-2569
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, and 2007 SP2 does not properly handle an unspecified size field in certain older file formats, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted Publisher file, aka "Size Value Heap Corruption in pubconv.dll Vulnerability."
pubconv.dll (también conocido como el Publisher Converter DLL) en Microsoft Publisher 2002 SP3, 2003 SP3, y 2007 SP2, no maneja adecuadamente un tamaño de campo sin especificar en determinados formatos antiguos de archivos, lo que permite a atacantes remotos ejecutar código de su elección o provocar una denegación de servicio (corrupción de memoria dinámica) a través de una archivo de Publisher manipulado. También conocida como "Size Value Heap Corruption in pubconv.dll Vulnerability".
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-06-30 CVE Reserved
- 2010-12-16 CVE Published
- 2024-08-07 CVE Updated
- 2024-11-03 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id?1024885 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA10-348A.html | Third Party Advisory | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11555 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-103 | 2018-10-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Publisher Search vendor "Microsoft" for product "Publisher" | 2002 Search vendor "Microsoft" for product "Publisher" and version "2002" | sp3 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Publisher Search vendor "Microsoft" for product "Publisher" | 2003 Search vendor "Microsoft" for product "Publisher" and version "2003" | sp3 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Publisher Search vendor "Microsoft" for product "Publisher" | 2007 Search vendor "Microsoft" for product "Publisher" and version "2007" | sp2 |
Affected
|