ZeroHour

CVE-2019-5005

CVSS 3.0
5.5 medium
EPSS
1%p68
Published
()
Modified
Description

An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. They allowed Denial of Service (application crash) via image data, because two bytes are written to the end of the allocated memory without judging whether this will cause corruption.

Vendors
foxitsoftware
Products
foxit reader, phantompdf
Weakness
CWE-787
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.