CVE-2019-6984 describes a Use-After-Free or Type Confusion vulnerability in the Foxit 3D Plugin Beta for Foxit Reader and PhantomPDF, affecting versions prior to 9.4.0.16807. This medium-severity vulnerability (CVSS 6.5) can be triggered remotely by a user opening a specially crafted PDF file with embedded 3D content, leading to application crashes due to a wild pointer. While it has no known active exploits, public exploit code, or significant community discussion, it represents a denial-of-service risk to affected Foxit products.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.4.0.16807CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:3d:*:*:*:*:*:foxit_reader:*:* | ||
< 9.4.0.16807CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:3d:*:*:*:*:*:phantompdf:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.