CVE-2018-3842
published 2018-04-19CVE-2018-3842: An exploitable use of an uninitialized pointer vulnerability exists in the JavaScript engine in Foxit PDF Reader version 9.0.1.1049. A specially crafted PDF…
PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.22%
86.9th percentile
An exploitable use of an uninitialized pointer vulnerability exists in the JavaScript engine in Foxit PDF Reader version 9.0.1.1049. A specially crafted PDF document can lead to a dereference of an uninitialized pointer which, if under attacker control, can result in arbitrary code execution. An attacker needs to trick the user to open a malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxitsoftware | foxit_reader | — | — |
| talos | foxit | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Multiple Issues in Foxit PDF Reader
blogs_talos·2018-04-19·CVSS 8.8
CVE-2017-14458 [HIGH] Vulnerability Spotlight: Multiple Issues in Foxit PDF Reader
### Overview Talos is disclosing five vulnerabilities in Foxit PDF Reader.Foxit PDF Readeris a popular free program for viewing, creating, and editing PDF documents. It is commonly used as an alternative to Adobe Acrobat Reader and has a widely used browser plugin available. Update to the current version ofFoxit PDF Reader.
### DetailsVulnerabilities Discovered by Aleksandar Nikolic
#### TALOS-2017-0506 TALOS-2017-0506 / CVE-2017-14458 in an exploitable use-after-free vulnerability that exists specifically in the JavaScript engine of Foxit PDF Reader. When executing embedded JavaScript code, a document can be closed, which essentially frees up a lot of used objects, but the JavaScript can continue to execute. Taking advantage of this, a specially crafted PDF document can trigger a previo
Talos
Vulnerability Spotlight: Multiple Issues in Foxit PDF Reader
blogs_talos·2018-04-19·CVSS 8.8
[HIGH] Vulnerability Spotlight: Multiple Issues in Foxit PDF Reader
## Vulnerability Spotlight: Multiple Issues in Foxit PDF Reader
## Overview Talos is disclosing five vulnerabilities in Foxit PDF Reader. Foxit PDF Reader is a popular free program for viewing, creating, and editing PDF documents. It is commonly used as an alternative to Adobe Acrobat Reader and has a widely used browser plugin available. Update to the current version of Foxit PDF Reader .
## Details Vulnerabilities Discovered by Aleksandar Nikolic
## TALOS-2017-0506 TALOS-2017-0506 / CVE-2017-14458 in an exploitable use-after-free vulnerability that exists specifically in the JavaScript engine of Foxit PDF Reader. When executing embedded JavaScript code, a document can be closed, which essentially frees up a lot of used objects, but the JavaScript can continue to execute. Taking advant
http://www.securityfocus.com/bid/103942http://www.securitytracker.com/id/1040733https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0525http://www.securityfocus.com/bid/103942http://www.securitytracker.com/id/1040733https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0525
2018-04-19
Published