CVE-2015-8843
Last modified
CVE-2015-8843 is a vulnerability of currently unknown severity. The Foxit Cloud Update Service (FoxitCloudUpdateService) in Foxit Reader 6.1 through 6.2.x and 7.x before 7.2.2, when an update to the Cloud plugin is available, allows local users to gain privileges by writing crafted data to a shared memory region, which triggers memory corruption.. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
The Foxit Cloud Update Service (FoxitCloudUpdateService) in Foxit Reader 6.1 through 6.2.x and 7.x before 7.2.2, when an update to the Cloud plugin is available, allows local users to gain privileges by writing crafted data to a shared memory region, which triggers memory corruption.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Foxitsoftware | Foxit Reader | 6.1 |
| Foxitsoftware | Foxit Reader | 6.1.2 |
| Foxitsoftware | Foxit Reader | 6.1.4 |
| Foxitsoftware | Foxit Reader | 6.2 |
| Foxitsoftware | Foxit Reader | 6.2.1 |
| Foxitsoftware | Foxit Reader | 7.0 |
| Foxitsoftware | Foxit Reader | 7.0.1 |
| Foxitsoftware | Foxit Reader | 7.0.6 |
| Foxitsoftware | Foxit Reader | 7.1.5 |
| Foxitsoftware | Foxit Reader | 7.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-8843?
How severe is CVE-2015-8843?
How do I fix CVE-2015-8843?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-8837Stack-based buffer overflow in the isofs_real_readdir functi…
- CVE-2015-8838ext/mysqlnd/mysqlnd.c in PHP before 5.4.43, 5.5.x before 5.5…
- CVE-2015-8839Multiple race conditions in the ext4 filesystem implementati…5.1
- CVE-2015-8840The XML Data Archiving Service (XML DAS) in SAP NetWeaver AS…8.8
- CVE-2015-8841Heap-based buffer overflow in the Archive support module in …9.8
- CVE-2015-8842tmpfiles.d/systemd.conf in systemd before 229 uses weak perm…
- CVE-2015-8844The signal implementation in the Linux kernel before 4.3.5 o…
- CVE-2015-8845The tm_reclaim_thread function in arch/powerpc/kernel/proces…
- CVE-2015-8851node-uuid before 1.4.4 uses insufficiently random data to cr…7.5
- CVE-2015-8852Varnish 3.x before 3.0.7, when used in certain stacked insta…
- CVE-2015-8853The (1) S_reghop3, (2) S_reghop4, and (3) S_reghopmaybe3 fun…
- CVE-2015-8854The marked package before 0.3.4 for Node.js allows attackers…7.5
Are you affected by CVE-2015-8843?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
