CVE-2019-5005

MEDIUM

Foxit Reader & PhantomPDF <9.4 - DoS

Title source: llm
STIX 2.1

Description

An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. They allowed Denial of Service (application crash) via image data, because two bytes are written to the end of the allocated memory without judging whether this will cause corruption.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.foxitsoftware.com/support/security-bulletins.php

Scores

CVSS v3 5.5
EPSS 0.0008
EPSS Percentile 23.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-787
Status published
Products (2)
foxitsoftware/foxit_reader < 9.4
foxitsoftware/phantompdf < 9.4
Published Jan 03, 2019
Tracked Since Feb 18, 2026