5.5
CVE-2021-40326
- EPSS 0.06%
- Published 29.08.2022 05:15:07
- Last modified 21.11.2024 06:23:51
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An attacker can write to an arbitrary file, and display controlled contents, during signature verification.
Data is provided by the National Vulnerability Database (NVD)
Foxit ≫ Pdf Editor Version >= 11.0 < 11.1
Foxit ≫ Pdf Reader Version >= 11.0 < 11.1
Foxit ≫ Phantompdf Version < 10.1.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.06% | 0.2 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.