PoC Index

CVE-2020-11493

HIGH 8.1EPSS 0.9%

In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to Stream without concern for a crafted XObject.

CVSS v3.1
8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
CVSS v2.0
5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
EPSS
0.93% chance of exploitation in the next 30 days, 58th percentile
Published
2020-09-04
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related