Use-After-Free Vulnerability in Foxit PDF Reader Software
CVE-2018-3942

8HIGH

Key Information:

Vendor

Foxit

Vendor
CVE Published:
8 October 2018

What is CVE-2018-3942?

An exploitable use-after-free vulnerability is present in the JavaScript engine of Foxit PDF Reader. This flaw arises when a specific PDF is manipulated to interact with a previously freed object in memory, leading to the potential execution of arbitrary code. An attacker can leverage this vulnerability by deceiving the user into opening a specially crafted PDF document. Ensuring users are aware of the risks associated with untrusted files is essential to mitigating this threat.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Foxit PDF Reader 9.1.0.5096

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.