CVE-2020-35990
published 2023-08-11CVE-2020-35990: Buffer Overflow vulnerability in cFilenameInit parameter in browseForDoc function in Foxit Software Foxit PDF Reader version 10.1.0.37527, allows local…
PriorityP417medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.21%
10.9th percentile
Buffer Overflow vulnerability in cFilenameInit parameter in browseForDoc function in Foxit Software Foxit PDF Reader version 10.1.0.37527, allows local attackers to cause a denial of service (DoS) via crafted .pdf file.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxit | pdf_reader | <= 10.1.0.37527 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Foxit PDF Reader 10.1.0.37527 browseForDoc cFilenameInit buffer overflow
vuldb·2026-07-10·CVSS 5.5
CVE-2020-35990 [MEDIUM] Foxit PDF Reader 10.1.0.37527 browseForDoc cFilenameInit buffer overflow
A vulnerability described as critical has been identified in Foxit PDF Reader 10.1.0.37527. This vulnerability affects the function browseForDoc. The manipulation of the argument cFilenameInit results in buffer overflow.
This vulnerability is identified as CVE-2020-35990. The attack can be executed remotely. There is not any exploit available.
GHSA
GHSA-6qhr-cpg4-c66p: Buffer Overflow vulnerability in cFilenameInit parameter in browseForDoc function in Foxit Software Foxit PDF Reader version 10
ghsa_unreviewed·2023-08-11
CVE-2020-35990 [MEDIUM] CWE-120 GHSA-6qhr-cpg4-c66p: Buffer Overflow vulnerability in cFilenameInit parameter in browseForDoc function in Foxit Software Foxit PDF Reader version 10
Buffer Overflow vulnerability in cFilenameInit parameter in browseForDoc function in Foxit Software Foxit PDF Reader version 10.1.0.37527, allows local attackers to cause a denial of service (DoS) via crafted .pdf file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-08-11
Published