CVE-2018-9947 is a critical remote code execution vulnerability affecting Foxit Reader and PhantomPDF versions 9.0.0.29935 and earlier. It stems from improper validation of user-supplied data when parsing BMP images, leading to a heap-based buffer overflow. This vulnerability has a CVSS score of 8.8 (High), requiring user interaction (e.g., opening a malicious file) for exploitation, which could result in arbitrary code execution under the current user's context. While no public exploits, Metasploit modules, or active exploitation are reported, its high severity warrants attention. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.0.1.1049CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:foxit_reader:*:*:*:*:*:*:*:* | ||
<= 9.0.1.1049CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.