CVE-2018-9948 is a sensitive information disclosure vulnerability affecting Foxit Reader 9.0.0.29935 and PhantomPDF, stemming from improper pointer initialization when handling typed arrays. It carries a CVSS score of 6.5 (Medium), requiring user interaction (e.g., opening a malicious file) for exploitation, and could lead to high confidentiality impact. While not in the KEV catalog, exploit code, including Metasploit modules and ExploitDB entries for both information disclosure and potential RCE, is publicly available. Despite this, there is minimal community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.0.1.1049CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:foxit_reader:*:*:*:*:*:*:*:* | ||
<= 9.0.1.1049CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.