CVE-2016-8875

MEDIUM

Foxit Reader & PhantomPDF <8.1 (Win) - DoS

Title source: llm

Description

The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image, aka "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at ConvertToPDF_x86!CreateFXPDFConvertor."

Scores

CVSS v3 5.3
EPSS 0.0009
EPSS Percentile 25.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

Classification

CWE
CWE-125
Status published

Affected Products (3)

foxitsoftware/phantompdf < 8.0.5
foxitsoftware/reader < 8.0.5
n/a/n/a

Timeline

Published Oct 31, 2016
Tracked Since Feb 18, 2026