CVE-2018-3842Access of Uninitialized Pointer in Foxit

Severity
8.8HIGHNVD
EPSS
4.1%
top 11.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 19
Latest updateMay 13

Description

An exploitable use of an uninitialized pointer vulnerability exists in the JavaScript engine in Foxit PDF Reader version 9.0.1.1049. A specially crafted PDF document can lead to a dereference of an uninitialized pointer which, if under attacker control, can result in arbitrary code execution. An attacker needs to trick the user to open a malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5talos/foxitFoxit Software Foxit PDF Reader 9.0.1.1049

🔴Vulnerability Details

2
GHSA
GHSA-3wmv-527f-7jxv: An exploitable use of an uninitialized pointer vulnerability exists in the JavaScript engine in Foxit PDF Reader version 92022-05-13
CVEList
CVE-2018-3842: An exploitable use of an uninitialized pointer vulnerability exists in the JavaScript engine in Foxit PDF Reader version 92018-04-19

🕵️Threat Intelligence

2
Talos
Vulnerability Spotlight: Multiple Issues in Foxit PDF Reader2018-04-19
Talos
Vulnerability Spotlight: Multiple Issues in Foxit PDF Reader2018-04-19
CVE-2018-3842 — Access of Uninitialized Pointer | cvebase