CVE-2018-19448
17.06.2019, 20:15
In Foxit Reader SDK (ActiveX) Professional 5.4.0.1031, an uninitialized object in IReader_ContentProvider::GetDocEventHandler occurs when embedding the control into Office documents. By opening a specially crafted document, an attacker can trigger an out of bounds write condition, possibly leveraging this to gain remote code execution.Enginsight
Vendor | Product | Version |
---|---|---|
foxitsoftware | foxit_pdf_sdk_activex | 𝑥 ≤ 5.5.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration