CVE-2015-8580

Foxit Reader <7.2.2, Foxit PhantomPDF <7.2.2 - Use After Free

Title source: llm
STIX 2.1

Description

Multiple use-after-free vulnerabilities in the (1) Print method and (2) App object handling in Foxit Reader before 7.2.2 and Foxit PhantomPDF before 7.2.2 allow remote attackers to execute arbitrary code via a crafted PDF document.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-15-622
Third Party Advisory, VDB Entry x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-15-623

Scores

EPSS 0.0068
EPSS Percentile 71.7%

Details

Status published
Products (2)
foxitsoftware/foxit_reader < 7.2.0.722
foxitsoftware/phantompdf < 7.2.0.722
Published Dec 16, 2015
Tracked Since Feb 18, 2026