cbcvebase.
CVE-2018-3942
published 2018-10-08

CVE-2018-3942: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.0.5096. A specially crafted PDF…

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability.

Affected

3 ranges
VendorProductVersion rangeFixed in
foxit_softwarefoxit_pdf_reader
foxitsoftwarephantompdf<= 9.2.0.9297
foxitsoftwarereader<= 9.2.0.9297