CVE-2010-20010 describes a stack buffer overflow vulnerability in Foxit PDF Reader before version 4.2.0.0928. This flaw occurs when the software fails to properly bound-check the /Title entry in a PDF's Info dictionary, allowing a specially crafted PDF with an overlong Title string to corrupt the Structured Exception Handler (SEH) chain. The vulnerability carries a high CVSS score of 8.4, indicating that an attacker can achieve arbitrary code execution in the context of the user by simply having them open a malicious PDF file. While not listed on KEV, a Metasploit module exists for this vulnerability, and it has garnered significant community discussion, suggesting its exploitability is well-known.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 4.2.0.0928CPE match | cpe:2.3:a:foxitsoftware:pdf_reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.