4.7
CVSSv3

CVE-2017-6883

Published: 14/03/2017 Updated: 03/10/2019
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
CVSS v3 Base Score: 4.7 | Impact Score: 3.6 | Exploitability Score: 1
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N

Vulnerability Summary

The ConvertToPDF plugin in Foxit Reader prior to 8.2.1 and PhantomPDF prior to 8.2.1 on Windows, when the gflags app is enabled, allows remote malicious users to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image. The vulnerability could lead to information disclosure; an attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

Vulnerable Product Search on Vulmon Subscribe to Product

foxitsoftware foxit reader

foxitsoftware phantompdf