← Back to browse · API

CVE-2018-3956

Severity
MEDIUM
CVSS
6.8
EPSS
0.49566
Risk score
44.55
CISA KEV
No
PoC
No
Published
2019-01-30
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2018-15742, GHSA-PHP8-5JRG-X8G2
Products
Foxit:Foxit Foxit Software PDF Reader 9.1.0.5096.
Sources
euvd EUVD-2018-15742

Description

An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Software's PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger an out-of-bounds read, which can disclose sensitive memory content and aid in exploitation when coupled with another vulnerability. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

References