CVE-2018-19447Out-of-bounds Write in Foxit PDF SDK Activex

Severity
7.8HIGHNVD
EPSS
0.3%
top 45.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 17
Latest updateMay 24

Description

A stack-based buffer overflow can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when parsing the URI string. An attacker can leverage this to gain remote code execution.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4xh9-c7jc-9fc5: A stack-based buffer overflow can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 52022-05-24
CVEList
CVE-2018-19447: A stack-based buffer overflow can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 52019-06-17
CVE-2018-19447 — Out-of-bounds Write | cvebase