CVE-2019-5005Out-of-bounds Write in Foxit Reader

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 76.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 3
Latest updateMay 13

Description

An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. They allowed Denial of Service (application crash) via image data, because two bytes are written to the end of the allocated memory without judging whether this will cause corruption.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pw67-f78v-48j2: An issue was discovered in Foxit Reader and PhantomPDF before 92022-05-13
CVEList
CVE-2019-5005: An issue was discovered in Foxit Reader and PhantomPDF before 92019-01-03
CVE-2019-5005 — Out-of-bounds Write in Foxit Reader | cvebase