cbcvebase.
CVE-2015-2790
published 2015-03-30

CVE-2015-2790: Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted (1)…

PriorityP334medium4.3CVSS 2.0
AVNACMAuNCNINAP
EXPLOIT
EPSS
24.52%
97.6th percentile
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted (1) Ubyte Size in a DataSubBlock structure or (2) LZWMinimumCodeSize in a GIF image.

Affected

3 ranges
VendorProductVersion rangeFixed in
foxitsoftwareenterprise_reader<= 7.0.6.1126
foxitsoftwarefoxit_reader<= 7.0.6.1126
foxitsoftwarephantompdf<= 7.0.6.1126

Detection & IOCsextracted from sources · hover to see the quote

urlhttp://protekresearchlab.com/exploits/PRL-2015-02.gif
urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/36335.gif
urlhttp://protekresearchlab.com/exploits/PRL-2015-01.gif
urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/36334.gif
  • Trigger vector is a crafted GIF file with a malformed Ubyte Size field in a DataSubBlock structure, delivered to Foxit Reader/Enterprise Reader/PhantomPDF before 7.1 on Windows.
  • Trigger vector is a crafted GIF file with a malformed LZWMinimumCodeSize field, delivered to Foxit Reader/Enterprise Reader/PhantomPDF before 7.1 on Windows.
  • ·Vulnerability confirmed in Foxit Reader 7.x; other versions may also be affected. Fixed in Foxit Reader 7.1, Foxit Enterprise Reader 7.1, and Foxit PhantomPDF 7.1 released 2015-03-09.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.