7.8
CVSSv3

CVE-2020-35931

Published: 31/12/2020 Updated: 08/09/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Foxit Reader prior to 10.1.1 (and prior to 4.1.1 on macOS) and PhantomPDF prior to 9.7.5 and 10.x prior to 10.1.1 (and prior to 4.1.1 on macOS). An attacker can spoof a certified PDF document via an Evil Annotation Attack because the products fail to consider a null value for a Subtype entry of the Annotation dictionary, in an incremental update.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

foxitsoftware foxit_reader

foxitsoftware phantompdf