AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2010-2746

HIGH · CVSS 7.6 EPSS 36.24%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2010-10-13 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2010-2746
Severity
HIGH
CVSS
7.6
EPSS
36.24%
Microsoft Windows

Original NVD Description

Heap-based buffer overflow in Comctl32.dll (aka the common control library) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when a third-party SVG viewer is used, allows remote attackers to execute arbitrary code via a crafted HTML document that triggers unspecified messages from this viewer, aka "Comctl32 Heap Overflow Vulnerability."