Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.813264
Category:General
Title:Foxit PhantomPDF 'JavaScript' Remote Code Execution Vulnerabilities - Windows
Summary:Foxit PhantomPDF is prone to multiple code execution vulnerabilities.
Description:Summary:
Foxit PhantomPDF is prone to multiple code execution vulnerabilities.

Vulnerability Insight:
Multiple flaws exist due to:

- The user-after-free vulnerability that exists in the JavaScript, When
executing embedded JavaScript code a document can be cloned. which frees
a lot of used objects, but the JavaScript can continue to execute.

- The use-after-free vulnerability found in the Javascript engine that can
result in remote code execution.

Vulnerability Impact:
Successful exploitation will allow an
attacker to execute arbitrary code.

Affected Software/OS:
Foxit PhantomPDF versions before 9.2 on Windows.

Solution:
Upgrade to Foxit PhantomPDF version 9.2
or later. Please see the references for more information.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-14295
https://zerodayinitiative.com/advisories/ZDI-18-755
Common Vulnerability Exposure (CVE) ID: CVE-2018-17706
https://zerodayinitiative.com/advisories/ZDI-18-1095
Common Vulnerability Exposure (CVE) ID: CVE-2018-17624
https://zerodayinitiative.com/advisories/ZDI-18-1105
Common Vulnerability Exposure (CVE) ID: CVE-2018-17622
https://zerodayinitiative.com/advisories/ZDI-18-1103
Common Vulnerability Exposure (CVE) ID: CVE-2018-17620
https://zerodayinitiative.com/advisories/ZDI-18-1101
Common Vulnerability Exposure (CVE) ID: CVE-2018-17621
https://zerodayinitiative.com/advisories/ZDI-18-1102
Common Vulnerability Exposure (CVE) ID: CVE-2018-17618
https://zerodayinitiative.com/advisories/ZDI-18-1099
Common Vulnerability Exposure (CVE) ID: CVE-2018-17619
https://zerodayinitiative.com/advisories/ZDI-18-1100
Common Vulnerability Exposure (CVE) ID: CVE-2018-17617
https://zerodayinitiative.com/advisories/ZDI-18-1098
Common Vulnerability Exposure (CVE) ID: CVE-2018-17615
https://zerodayinitiative.com/advisories/ZDI-18-1096
Common Vulnerability Exposure (CVE) ID: CVE-2018-17616
https://zerodayinitiative.com/advisories/ZDI-18-1097
CopyrightCopyright (C) 2018 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.