CVE-2019-14209

CRITICAL

Foxit PhantomPDF <8.3.10 - Memory Corruption

Title source: llm
STIX 2.1

Description

An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to Heap Corruption due to data desynchrony when adding AcroForm.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://www.foxitsoftware.com/support/security-bulletins.php

Scores

CVSS v3 9.8
EPSS 0.0004
EPSS Percentile 10.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (1)
foxitsoftware/phantompdf < 8.3.10
Published Jul 21, 2019
Tracked Since Feb 18, 2026