← Back

CVE-2018-3939

nvd nist
Published: Aug 1, 2018Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

Affected (2)

2 products
Foxit Reader
Phantompdf
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 9.1.0.5096
Up to 9.1.0.5096
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (3)

Source: talos-cna@cisco.com
ExploitTechnical DescriptionThird Party Advisory
Source: nvd@nist.gov
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical DescriptionThird Party Advisory

Timeline

No history available yet.