CVE-2010-20010

Foxit PDF Reader before 4.2.0.0928 does not properly bound-check the /Title entry in the PDF Info dictionary. A specially crafted PDF with an overlong Title string can overflow a fixed-size stack buffer, corrupt the Structured Exception Handler (SEH) chain, and lead to arbitrary code execution in the context of the user who opens the file.

Scoring

Severity
HIGH
CVSS base score
8.4
CVSS vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS probability
7.02%
CWE
CWE-121
Published
2025-08-20
Last modified
2026-05-15

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs