CVE-2018-3956
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Software's PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger an out-of-bounds read, which can disclose sensitive memory content and aid in exploitation when coupled with another vulnerability. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Una vulnerabilidad de lectura fuera de límites explotable en la gestión de determinados atributos de elementos XFA de la versión 9.1.0.5096 del lector PDF de Foxit Software. Un documento PDF especialmente manipulado puede provocar una lectura fuera de límites, lo que puede divulgar contenido sensible de la memoria y servir de ayuda en tareas de explotación cuando va acompañado de otra vulnerabilidad. Un atacante necesita engañar a un usuario para que abra el archivo malicioso para desencadenar esta vulnerabilidad. Si la extensión del plugin del navegador está habilitada, visitar un sitio malicioso también puede desencadenar esta vulnerabilidad.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-01-02 CVE Reserved
- 2019-01-30 CVE Published
- 2023-10-31 EPSS Updated
- 2024-09-16 CVE Updated
- 2024-09-16 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0626 | 2024-09-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Foxitsoftware Search vendor "Foxitsoftware" | Phantompdf Search vendor "Foxitsoftware" for product "Phantompdf" | <= 9.3.0.10826 Search vendor "Foxitsoftware" for product "Phantompdf" and version " <= 9.3.0.10826" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Foxitsoftware Search vendor "Foxitsoftware" | Reader Search vendor "Foxitsoftware" for product "Reader" | <= 9.3.0.10826 Search vendor "Foxitsoftware" for product "Reader" and version " <= 9.3.0.10826" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|