CVE-2013-10068
published 2025-08-05CVE-2013-10068: Foxit Reader versions through 5.4.5.0114, including the bundled Foxit Reader Plugin 2.2.1.530, contains a stack-based buffer overflow vulnerability in the…
PriorityP355critical9.4CVSS 4.0
AVNACLATNPRNUIAVCHVIHVAHSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EXPLOIT
EPSS
0.96%
57.6th percentile
Foxit Reader versions through 5.4.5.0114, including the bundled Foxit Reader Plugin 2.2.1.530, contains a stack-based buffer overflow vulnerability in the npFoxitReaderPlugin.dll module. When a PDF file is loaded from a remote host, an overly long query string in the URL can overflow a buffer, allowing remote attackers to execute arbitrary code.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxit | foxit_reader | <= 5.4.5.0114 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts by monitoring for overly long query strings in URLs used to load PDF files via the Foxit Reader browser plugin (npFoxitReaderPlugin.dll). ↗
- →Monitor for stack-based buffer overflow activity originating from npFoxitReaderPlugin.dll when PDF files are loaded from remote hosts. ↗
- →Flag browser processes (e.g., Firefox) spawning unexpected child processes or shellcode execution when npFoxitReaderPlugin.dll is loaded, particularly on Windows 7 SP1 with Firefox 18.0. ↗
- ·Exploitation requires the victim to load a PDF from a remote host via the browser plugin; the overflow is triggered specifically through the URL query string, not the PDF content itself. ↗
- ·The Metasploit module targets a specific tested environment; exploitation reliability may vary outside of Windows 7 SP1 / Firefox 18.0 / Foxit Reader 5.4.4.11281. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Foxit Reader 5.4.4.1128 npFoxitReaderPlugin.dll memory corruption (EUVD-2013-7278 / EDB-23944)
vuldb·2026-05-26·CVSS 9.4
CVE-2013-10068 [CRITICAL] Foxit Reader 5.4.4.1128 npFoxitReaderPlugin.dll memory corruption (EUVD-2013-7278 / EDB-23944)
A vulnerability, which was classified as critical, was found in Foxit Reader 5.4.4.1128. The affected element is an unknown function in the library npFoxitReaderPlugin.dll. Such manipulation leads to memory corruption.
This vulnerability is referenced as CVE-2013-10068. It is possible to launch the attack remotely. Furthermore, an exploit is available.
You should upgrade the affected component.
GHSA
GHSA-7v2f-pw6h-v9vh: Foxit Reader Plugin version 2
ghsa_unreviewed·2025-08-05
CVE-2013-10068 [CRITICAL] CWE-121 GHSA-7v2f-pw6h-v9vh: Foxit Reader Plugin version 2
Foxit Reader Plugin version 2.2.1.530, bundled with Foxit Reader 5.4.4.11281, contains a stack-based buffer overflow vulnerability in the npFoxitReaderPlugin.dll module. When a PDF file is loaded from a remote host, an overly long query string in the URL can overflow a buffer, allowing remote attackers to execute arbitrary code.
No detection rules found.
No writeups or analysis indexed.
https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/browser/foxit_reader_plugin_url_bof.rbhttps://www.exploit-db.com/exploits/23944https://www.exploit-db.com/exploits/24502https://www.tenable.com/plugins/nessus/64094https://www.vulncheck.com/advisories/foxit-reader-plugin-url-processing-buffer-overflow
2025-08-05
Published