CVE-2010-2883: Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability

Published Sep 9, 2010
·
Updated

Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

Other sources

Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information.

Affected Software

58 affected components
Adobe Acrobat and Reader
All of the following
Any of the following
Adobe Acrobat>=8.0<8.2.5
Adobe Acrobat>=9.0<9.4
Any of the following
Apple macOS
Microsoft Windows
All of the following
Any of the following
Adobe Acrobat Reader>=8.0<8.2.5
Adobe Acrobat Reader>=9.0<9.4
Any of the following
Apple macOS
Microsoft Windows
Adobe Acrobat<=9.3.4
Adobe Acrobat=8.0
Adobe Acrobat=8.1
Adobe Acrobat=8.1.1
Adobe Acrobat=8.1.2
Adobe Acrobat=8.1.3
Adobe Acrobat=8.1.4
Adobe Acrobat=8.1.5
Adobe Acrobat=8.1.6
Adobe Acrobat=8.1.7
Adobe Acrobat=8.2
Adobe Acrobat=8.2.1
Adobe Acrobat=8.2.2
Adobe Acrobat=8.2.4
Adobe Acrobat=9.0
Adobe Acrobat=9.1
Adobe Acrobat=9.1.1
Adobe Acrobat=9.1.2
Adobe Acrobat=9.1.3
Adobe Acrobat=9.2
Adobe Acrobat=9.3
Adobe Acrobat=9.3.1
Adobe Acrobat=9.3.2
Adobe Acrobat=9.3.3
Apple iOS and macOS
Microsoft Windows
Adobe Acrobat Reader<=9.3.4
Adobe Acrobat Reader=8.0
Adobe Acrobat Reader=8.1
Adobe Acrobat Reader=8.1.1
Adobe Acrobat Reader=8.1.2
Adobe Acrobat Reader=8.1.4
Adobe Acrobat Reader=8.1.5
Adobe Acrobat Reader=8.1.6
Adobe Acrobat Reader=8.1.7
Adobe Acrobat Reader=8.2.1
Adobe Acrobat Reader=8.2.2
Adobe Acrobat Reader=8.2.3
Adobe Acrobat Reader=8.2.4
Adobe Acrobat Reader=9.0
Adobe Acrobat Reader=9.1
Adobe Acrobat Reader=9.1.1
Adobe Acrobat Reader=9.1.2
Adobe Acrobat Reader=9.1.3
Adobe Acrobat Reader=9.2
Adobe Acrobat Reader=9.3
Adobe Acrobat Reader=9.3.1
Adobe Acrobat Reader=9.3.2
Adobe Acrobat Reader=9.3.3

Event History

Sep 9, 2010
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
10:00 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·10:00 PM
DescriptionSeverityWeaknessAffected Software
Jun 8, 2022
Known Exploited
via CISA·12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2010-2883?

CVE-2010-2883 has a critical severity rating due to its potential for remote code execution and denial-of-service attacks.

2

How do I fix CVE-2010-2883?

To address CVE-2010-2883, it is recommended to update Adobe Acrobat and Reader to version 9.4 or later for 9.x and version 8.2.5 or later for 8.x.

3

Which versions of Adobe Acrobat are affected by CVE-2010-2883?

Affected versions of Adobe Acrobat include 8.x before 8.2.5 and 9.x before 9.4.

4

Is Adobe Reader vulnerable to CVE-2010-2883?

Yes, Adobe Reader versions 8.x before 8.2.5 and 9.x before 9.4 are vulnerable to CVE-2010-2883.

5

What type of vulnerability is CVE-2010-2883?

CVE-2010-2883 is a stack-based buffer overflow vulnerability located in the CoolType.dll component of Adobe Acrobat and Reader.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203