CVE-2010-2746 (CNNVD-201010-129)
中文标题:
Microsoft Windows Comctl32.dll堆缓冲区溢出漏洞
英文标题:
Heap-based buffer overflow in Comctl32.dll (aka the common control library) in Microsoft Windows XP ...
漏洞描述
中文描述:
Comctl32.dll是Windows应用程序公用GUI图形用户界面模块。 Microsoft Windows XP SP2和SP3版本,Windows Server 2003 SP2版本,Windows Vista SP1和SP2版本,Windows Server 2008 Gold,SP2和R2版本,以及Windows 7中的Comctl32.dll(又名通用控制库)文件中存在基于堆的缓冲区溢出漏洞。当第三方SVG查看器启用时,远程攻击者可以借助特制HTML文档(该文档能够触发查看器中的相关信息)执行任意代码。
英文描述:
Heap-based buffer overflow in Comctl32.dll (aka the common control library) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when a third-party SVG viewer is used, allows remote attackers to execute arbitrary code via a crafted HTML document that triggers unspecified messages from this viewer, aka "Comctl32 Heap Overflow Vulnerability."
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| microsoft | windows_2003_server | * | - | - |
cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*
|
| microsoft | windows_7 | * | - | - |
cpe:2.3:o:microsoft:windows_7:*:*:*:*:*:*:*:*
|
| microsoft | windows_7 | - | - | - |
cpe:2.3:o:microsoft:windows_7:-:*:*:*:*:*:*:*
|
| microsoft | windows_server_2003 | * | - | - |
cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*
|
| microsoft | windows_server_2008 | * | - | - |
cpe:2.3:o:microsoft:windows_server_2008:*:*:itanium:*:*:*:*:*
|
| microsoft | windows_server_2008 | r2 | - | - |
cpe:2.3:o:microsoft:windows_server_2008:r2:*:itanium:*:*:*:*:*
|
| microsoft | windows_vista | * | - | - |
cpe:2.3:o:microsoft:windows_vista:*:sp1:*:*:*:*:*:*
|
| microsoft | windows_xp | * | - | - |
cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*
|
| microsoft | windows_xp | - | - | - |
cpe:2.3:o:microsoft:windows_xp:-:sp2:x64:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
AV:N/AC:H/Au:N/C:C/I:C/A:C
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2010-2746 |
2025-11-11 15:18:17 | 2025-11-11 07:33:09 |
| NVD | nvd_CVE-2010-2746 |
2025-11-11 14:53:27 | 2025-11-11 07:41:57 |
| CNNVD | cnnvd_CNNVD-201010-129 |
2025-11-11 15:09:11 | 2025-11-11 07:49:46 |
| EXPLOITDB | exploitdb_EDB-15963 |
2025-11-11 15:05:57 | 2025-11-11 08:10:20 |
版本与语言
安全公告
变更历史
查看详细变更
- references_count: 4 -> 7
- tags_count: 0 -> 4
- data_sources: ['cnnvd', 'cve', 'nvd'] -> ['cnnvd', 'cve', 'exploitdb', 'nvd']
查看详细变更
- vulnerability_type: 未提取 -> 缓冲区错误
- cnnvd_id: 未提取 -> CNNVD-201010-129
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 7.6
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:H/Au:N/C:C/I:C/A:C
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 9
- data_sources: ['cve'] -> ['cve', 'nvd']