CVE-2018-20249
Last modified
CVE-2018-20249 is a vulnerability of currently unknown severity. In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing invalid xref entries using the DAOpenFile or DAOpenFileReadOnly functions may result in an access violation caused by out of bounds memory access.. EPSS estimates a 1.44% chance of exploitation in the next 30 days.
Description
In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing invalid xref entries using the DAOpenFile or DAOpenFileReadOnly functions may result in an access violation caused by out of bounds memory access.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Foxitsoftware | Quick Pdf Library | < 16.12 |
References
- http://www.securityfocus.com/bid/106306Third Party Advisory, VDB Entry
- https://www.foxitsoftware.com/support/security-bulletins.phpVendor Advisory
- http://www.securityfocus.com/bid/106306Third Party Advisory, VDB Entry
- https://www.foxitsoftware.com/support/security-bulletins.phpVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-20249?
How severe is CVE-2018-20249?
How do I fix CVE-2018-20249?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-20243The implementation of POST with the username and password in…7.5
- CVE-2018-20244In Apache Airflow before 1.10.2, a malicious admin user coul…
- CVE-2018-20245The LDAP auth backend (airflow.contrib.auth.backends.ldap_au…
- CVE-2018-20246Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2018-20247In Foxit Quick PDF Library (all versions prior to 16.12), is…7.8
- CVE-2018-20248In Foxit Quick PDF Library (all versions prior to 16.12), is…
- CVE-2018-2025IBM Spectrum Protect Backup-Archive Client and IBM Spectrum …4.4
- CVE-2018-20250In WinRAR versions prior to and including 5.61, There is pat…7.8
- CVE-2018-20251In WinRAR versions prior to and including 5.61, there is pat…
- CVE-2018-20252In WinRAR versions prior to and including 5.60, there is an …
- CVE-2018-20253In WinRAR versions prior to and including 5.60, There is an …
- CVE-2018-2026IBM Financial Transaction Manager 3.2.1 for Digital Payments…4.3
Are you affected by CVE-2018-20249?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
