CVE-2018-3956 is an out-of-bounds read vulnerability in Foxit PDF Reader and PhantomPDF versions 9.1.0.5096 and earlier, affecting Windows platforms. This flaw, triggered by specially crafted PDF documents or malicious websites via a browser plugin, can disclose sensitive memory content. Rated 7.1 HIGH, it requires user interaction (UI:R) but has low attack complexity (AC:L) and no authentication (PR:N), leading to high confidentiality impact (C:H). Currently, there is no public exploit code (Metasploit, Nuclei, ExploitDB) or evidence of active exploitation, and it lacks significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.3.0.10826CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:* | ||
<= 9.3.0.10826CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.