CVE-2018-14309
published 2018-07-31CVE-2018-14309: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.1.0.5096. User interaction is required to…
PriorityP351high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
2.77%
84.8th percentile
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.1.0.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the SeedValue Generic Object parameter provided to the signatureSetSeedValue function. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-6329.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxit | foxit_reader | — | — |
| foxitsoftware | foxit_reader | <= 9.1.0.5096 | — |
| foxitsoftware | phantompdf | <= 9.1.0.5096 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wmg8-34jg-v3f5: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9
ghsa_unreviewed·2022-05-13
CVE-2018-14309 [HIGH] CWE-416 GHSA-wmg8-34jg-v3f5: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.1.0.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the SeedValue Generic Object parameter provided to the signatureSetSeedValue function. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-6329.
GHSA
RichFaces vulnerable to Expression Language Injection
ghsa·2022-05-13
CVE-2018-12532 [CRITICAL] CWE-917 RichFaces vulnerable to Expression Language Injection
RichFaces vulnerable to Expression Language Injection
JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and execute arbitrary Java code via a MediaOutputResource's resource request, aka RF-14309.
Red Hat
RichFaces: Injection of arbitrary EL variable mapper allows to bypass mitigation of CVE-2015-0279 and thereby remote code execution
vendor_redhat·2018-05-30·CVSS 6.8
CVE-2018-12532 [MEDIUM] CWE-94 RichFaces: Injection of arbitrary EL variable mapper allows to bypass mitigation of CVE-2015-0279 and thereby remote code execution
RichFaces: Injection of arbitrary EL variable mapper allows to bypass mitigation of CVE-2015-0279 and thereby remote code execution
JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and execute arbitrary Java code via a MediaOutputResource's resource request, aka RF-14309.
Statement: This issue does not affect the following Red Hat products, as they do not include the vulnerable version of the RichFaces component:
Red Hat JBoss EAP 5.2
Red Hat JBoss Data Virtualization 6.4
Red Hat JBoss BRMS 5.3
Red Hat JBoss Operations Network 3.3
Package: RichFaces (JBoss Developer Studio 11) - Not affected
Package: RichFaces (Red Hat JBoss BRMS 5) - Not affected
Package: RichFaces (Red Hat JBoss Data Virtuali
No detection rules found.
No public exploits indexed.
2018-07-31
Published