CVE-2021-33794

CRITICAL

Foxit Reader and PhantomPDF < 10.1.4 - Information Disclosure or Denial of Service via XFA Form Tab Key Handling

Title source: llm
STIX 2.1

Description

Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 allow information disclosure or an application crash after mishandling the Tab key during XFA form interaction.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://www.foxitsoftware.com/support/security-bulletins.html

Scores

CVSS v3 9.1
EPSS 0.0003
EPSS Percentile 7.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Details

Status published
Products (2)
foxitsoftware/foxit_reader < 10.1.4
foxitsoftware/phantompdf < 10.1.4
Published Aug 11, 2021
Tracked Since Feb 18, 2026