cbcvebase.
CVE-2013-10068
published 2025-08-05

CVE-2013-10068: Foxit Reader versions through 5.4.5.0114, including the bundled Foxit Reader Plugin 2.2.1.530, contains a stack-based buffer overflow vulnerability in the…

PriorityP355critical9.4CVSS 4.0
AVNACLATNPRNUIAVCHVIHVAHSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EXPLOIT
EPSS
0.96%
57.6th percentile
Foxit Reader versions through 5.4.5.0114, including the bundled Foxit Reader Plugin 2.2.1.530, contains a stack-based buffer overflow vulnerability in the npFoxitReaderPlugin.dll module. When a PDF file is loaded from a remote host, an overly long query string in the URL can overflow a buffer, allowing remote attackers to execute arbitrary code.

Affected

1 ranges
VendorProductVersion rangeFixed in
foxitfoxit_reader<= 5.4.5.0114

Detection & IOCsextracted from sources · hover to see the quote

filenamenpFoxitReaderPlugin.dll
versionnpFoxitReaderPlugin.dll version 2.2.1.530
versionFoxit Reader version 5.4.4.11281
  • Detect exploitation attempts by monitoring for overly long query strings in URLs used to load PDF files via the Foxit Reader browser plugin (npFoxitReaderPlugin.dll).
  • Monitor for stack-based buffer overflow activity originating from npFoxitReaderPlugin.dll when PDF files are loaded from remote hosts.
  • Flag browser processes (e.g., Firefox) spawning unexpected child processes or shellcode execution when npFoxitReaderPlugin.dll is loaded, particularly on Windows 7 SP1 with Firefox 18.0.
  • ·Exploitation requires the victim to load a PDF from a remote host via the browser plugin; the overflow is triggered specifically through the URL query string, not the PDF content itself.
  • ·The Metasploit module targets a specific tested environment; exploitation reliability may vary outside of Windows 7 SP1 / Firefox 18.0 / Foxit Reader 5.4.4.11281.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.