8.1

CVE-2020-11493

In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to Stream without concern for a crafted XObject.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Foxitsoftware ≫ Phantompdf Version <= 9.7.2.29539
   Microsoft ≫ Windows Version -
Foxitsoftware ≫ Phantompdf Version <= 10.0.0.35798
   Microsoft ≫ Windows Version -
Foxitsoftware ≫ Reader Version <= 10.0.0.35798
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.93% 0.56
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:N/A:P
CWE-345 Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

https://www.foxitsoftware.com/support/security-bulletins.php
Vendor Advisory