CVE-2019-5031
An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.4.1.16828. A specially crafted PDF document can trigger an out-of-memory condition which isn't handled properly, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS probability
- 1.02%
- CWE
- CWE-703
- Published
- 2019-10-02
- Last modified
- 2026-03-14
Affected products
- n/a Foxit
Weakness type
Related vulnerabilities
- CVE-2023-0397 — DoS: Invalid Initialization in le_read_buffer_size_complete
- CVE-2021-3329 — DOS: Incorrect handling of the initial HCI ACL_MTU handshake packet leads to crash of bluetooth host layer
- CVE-2024-39815 — Vonets WiFi Bridges Improper Check or Handling of Exceptional Conditions
- CVE-2021-23859 — Denial of Service and Authentication Bypass Vulnerability in multiple Bosch products
- CVE-2023-5038 — Unauthenticated DoS
- CVE-2022-22265 — An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary m
- CVE-2024-21525 — All versions of the package node-twain are vulnerable to Improper Check or Handling of Exceptional Conditions due to the
- CVE-2026-20329 — Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Exceptional Conditions Handling Vulnerabilities