CVE-2020-11493
HIGH 8.1EPSS 0.9%
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to Stream without concern for a crafted XObject.
- CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H - CVSS v2.0
- 5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:P - EPSS
- 0.93% chance of exploitation in the next 30 days, 58th percentile
- Published
- 2020-09-04
- Updated
- 2024-08-04
Proof-of-concept exploits (1)
- fengjixuchui/CVE-2020-114931★ · 2020-06-01