ID

VAR-201006-0421


CVE

CVE-2010-2332


TITLE

iPhone Such as Impact PDF Reader Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2010-004883

DESCRIPTION

Impact Financials, Inc. Impact PDF Reader 2.0, 1.2, and other versions for iPhone and iPod touch allows remote attackers to cause a denial of service (server crash) via a "..." body in a POST request. Successful exploits may allow an attacker to crash the affected application, resulting in a denial-of-service condition. Impact PDF Reader 2.0 and 1.2 are vulnerable; other versions may also be affected. iPhone is a smartphone released by Apple

Trust: 1.98

sources: NVD: CVE-2010-2332 // JVNDB: JVNDB-2010-004883 // BID: 40858 // VULHUB: VHN-44937

AFFECTED PRODUCTS

vendor:impactfinancialsmodel:impact pdf readerscope:eqversion:2.0

Trust: 1.6

vendor:impactfinancialsmodel:impact pdf readerscope:eqversion:1.2

Trust: 1.6

vendor:impact financialsmodel:pdf readerscope:eqversion:2.0

Trust: 0.8

vendor:impact financialsmodel:pdf readerscope:eqversion:1.2

Trust: 0.8

vendor:impact financialsmodel:pdf readerscope:eqversion: -

Trust: 0.8

vendor:impactmodel:financials impact pdf readerscope:eqversion:2.0

Trust: 0.3

vendor:impactmodel:financials impact pdf readerscope:eqversion:1.2

Trust: 0.3

sources: BID: 40858 // JVNDB: JVNDB-2010-004883 // CNNVD: CNNVD-201006-328 // NVD: CVE-2010-2332

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2010-2332
value: MEDIUM

Trust: 1.0

NVD: CVE-2010-2332
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201006-328
value: MEDIUM

Trust: 0.6

VULHUB: VHN-44937
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2010-2332
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-44937
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-44937 // JVNDB: JVNDB-2010-004883 // CNNVD: CNNVD-201006-328 // NVD: CVE-2010-2332

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-44937 // JVNDB: JVNDB-2010-004883 // NVD: CVE-2010-2332

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201006-328

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201006-328

CONFIGURATIONS

sources: JVNDB: JVNDB-2010-004883

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-44937

PATCH

title:Impact PDF Readerurl:http://impactfinancials.com/impact_pdf_reader/index.html

Trust: 0.8

sources: JVNDB: JVNDB-2010-004883

EXTERNAL IDS

db:NVDid:CVE-2010-2332

Trust: 2.8

db:BIDid:40858

Trust: 2.0

db:EXPLOIT-DBid:13871

Trust: 1.7

db:JVNDBid:JVNDB-2010-004883

Trust: 0.8

db:CNNVDid:CNNVD-201006-328

Trust: 0.7

db:XFid:59433

Trust: 0.6

db:SEEBUGid:SSVID-69034

Trust: 0.1

db:VULHUBid:VHN-44937

Trust: 0.1

sources: VULHUB: VHN-44937 // BID: 40858 // JVNDB: JVNDB-2010-004883 // CNNVD: CNNVD-201006-328 // NVD: CVE-2010-2332

REFERENCES

url:http://www.securityfocus.com/bid/40858

Trust: 1.7

url:http://www.exploit-db.com/exploits/13871

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/59433

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2010-2332

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2010-2332

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/59433

Trust: 0.6

url:http://impactfinancials.com/impact_pdf_reader/index.html

Trust: 0.3

sources: VULHUB: VHN-44937 // BID: 40858 // JVNDB: JVNDB-2010-004883 // CNNVD: CNNVD-201006-328 // NVD: CVE-2010-2332

CREDITS

Nishant Das Patnaik

Trust: 0.3

sources: BID: 40858

SOURCES

db:VULHUBid:VHN-44937
db:BIDid:40858
db:JVNDBid:JVNDB-2010-004883
db:CNNVDid:CNNVD-201006-328
db:NVDid:CVE-2010-2332

LAST UPDATE DATE

2025-04-11T23:04:25.486000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-44937date:2017-08-17T00:00:00
db:BIDid:40858date:2015-04-13T21:02:00
db:JVNDBid:JVNDB-2010-004883date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-201006-328date:2021-08-16T00:00:00
db:NVDid:CVE-2010-2332date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:VULHUBid:VHN-44937date:2010-06-18T00:00:00
db:BIDid:40858date:2010-06-14T00:00:00
db:JVNDBid:JVNDB-2010-004883date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-201006-328date:2010-06-23T00:00:00
db:NVDid:CVE-2010-2332date:2010-06-18T20:30:01.327