Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.813157
Category:General
Title:Foxit PhantomPDF Multiple Vulnerabilities (Apr 2018) - Windows
Summary:Foxit PhantomPDF is prone to multiple vulnerabilities.
Description:Summary:
Foxit PhantomPDF is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws exist due to:

- An error where the application passes an insufficiently qualified path in
loading an external library when a user launches the application.

- A heap buffer overflow error.

- Multiple use-after-free errors.

- The use of uninitialized new 'Uint32Array' object or member variables in
'PrintParams' or 'm_pCurContex' objects.

- An incorrect memory allocation, memory commit, memory access, or array access.

- Type Confusion errors.

- An error in 'GoToE' & 'GoToR' Actions.

- An out-of-bounds read error in the '_JP2_Codestream_Read_SOT' function.

- An error since the application did not handle a COM object properly.

- An error allowing users to embed executable files.

Vulnerability Impact:
Successful exploitation will allow remote
attackers to cause a denial of service condition, execute arbitrary code and
gain access to sensitive data from memory.

Affected Software/OS:
Foxit PhantomPDF versions 9.0.1.1049 and
prior on windows

Solution:
Upgrade to Foxit Reader version 9.1 or later. Please see the references for more information.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-3842
BugTraq ID: 103942
http://www.securityfocus.com/bid/103942
https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0525
http://www.securitytracker.com/id/1040733
Common Vulnerability Exposure (CVE) ID: CVE-2017-17557
BugTraq ID: 103999
http://www.securityfocus.com/bid/103999
https://blog.0patch.com/2018/05/0patching-foxit-reader-buffer-oops.html
Common Vulnerability Exposure (CVE) ID: CVE-2017-14458
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0506
Common Vulnerability Exposure (CVE) ID: CVE-2018-3853
https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0536
Common Vulnerability Exposure (CVE) ID: CVE-2018-3850
https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0532
Common Vulnerability Exposure (CVE) ID: CVE-2018-3843
https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0526
Common Vulnerability Exposure (CVE) ID: CVE-2018-10302
https://srcincite.io/advisories/src-2018-0019/
CopyrightCopyright (C) 2018 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.