9.3

CVE-2010-1239

Exploit

Foxit Reader before 3.2.1.0401 allows remote attackers to (1) execute arbitrary local programs via a certain "/Type /Action /S /Launch" sequence, and (2) execute arbitrary programs embedded in a PDF document via an unspecified "/Launch /Action" sequence, a related issue to CVE-2009-0836.

Data is provided by the National Vulnerability Database (NVD)
FoxitsoftwareFoxit Reader Version <= 3.2.0.0303
FoxitsoftwareFoxit Reader Version2.3
FoxitsoftwareFoxit Reader Version3.0
FoxitsoftwareFoxit Reader Version3.1.0.0824
FoxitsoftwareFoxit Reader Version3.1.1.0901
FoxitsoftwareFoxit Reader Version3.1.1.0928
FoxitsoftwareFoxit Reader Version3.1.3.1030
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 5% 0.893
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.