CVE-2018-14310
published 2018-07-31CVE-2018-14310: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.1.0.5096. User interaction is required to…
PriorityP350high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
2.77%
84.8th percentile
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.1.0.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of events. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6330.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxit | foxit_reader | — | — |
| foxitsoftware | foxit_reader | <= 9.1.0.5096 | — |
| foxitsoftware | phantompdf | <= 9.1.0.5096 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c73g-45g2-gff2: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9
ghsa_unreviewed·2022-05-13
CVE-2018-14310 [HIGH] CWE-416 GHSA-c73g-45g2-gff2: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.1.0.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of events. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6330.
GHSA
Arbitrary code execution in Richfaces
ghsa·2022-05-13
CVE-2018-12533 [CRITICAL] CWE-917 Arbitrary code execution in Richfaces
Arbitrary code execution in Richfaces
JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via a /DATA/ substring in a path with an org.richfaces.renderkit.html.Paint2DResource$ImageData object, aka RF-14310.
Red Hat
RichFaces: Injection of arbitrary EL expressions allows remote code execution via org.richfaces.renderkit.html.Paint2DResource
vendor_redhat·2018-05-30·CVSS 9.8
CVE-2018-12533 [CRITICAL] CWE-94 RichFaces: Injection of arbitrary EL expressions allows remote code execution via org.richfaces.renderkit.html.Paint2DResource
RichFaces: Injection of arbitrary EL expressions allows remote code execution via org.richfaces.renderkit.html.Paint2DResource
JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via a /DATA/ substring in a path with an org.richfaces.renderkit.html.Paint2DResource$ImageData object, aka RF-14310.
Package: RichFaces (JBoss Developer Studio 11) - Will not fix
Package: RichFaces (Red Hat JBoss BRMS 5) - Will not fix
Package: RichFaces (Red Hat JBoss Data Virtualization 6) - Not affected
Package: RichFaces (Red Hat JBoss Enterprise Application Platform 6) - Not affected
Package: RichFaces (Red Hat JBoss SOA Platform 5) - Will not fix
No detection rules found.
No public exploits indexed.
2018-07-31
Published