CVE-2016-4061

Description

Foxit Reader and PhantomPDF before 7.3.4 on Windows allow remote attackers to cause a denial of service (application crash) via a crafted content stream.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.189

Associated Vulnerability

VulnerabilityOS Platform
Upgrade Foxit Reader Enterprise 7.3.0.118 to latest versionWindows
Upgrade foxit_reader 7.3.0.118 to latest versionWindows
Multiple Vulnerabilities are affected in Foxit PhantomPDF 8 (ML) 7.3.0.118Windows
Multiple Vulnerabilities are affected in Foxit PhantomPDF 8 7.3.0.118Windows
Multiple Vulnerabilities are affected in Foxit PhantomPDF 9 (EXE) 7.3.0.118Windows
Multiple Vulnerabilities are affected in Foxit PhantomPDF 9 (ML) (EXE) 7.3.0.118Windows
Multiple Vulnerabilities are affected in Foxit PhantomPDF 9 (ML) (MSI) 7.3.0.118Windows
Multiple Vulnerabilities are affected in Foxit PhantomPDF 9 (MSI) 7.3.0.118Windows
Multiple Vulnerabilities are affected in Foxit PhantomPDF Slim 7.3.0.118Windows
Multiple Vulnerabilities are affected in Foxit Reader 7.3.0.118Windows
Multiple Vulnerabilities are affected in Foxit Reader Enterprise 7.3.0.118Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-341798Foxit PDF Reader (MSI) (2024.3.0.26795) (Formerly Foxit Reader Enterprise)
PATCH-341796Foxit Reader (2024.3.0.26795)
PATCH-311706Foxit PhantomPDF 8 ML (8.3.12.47136)
PATCH-311625Foxit PhantomPDF 8 (8.3.12.47136)
PATCH-317726Foxit PhantomPDF 9 (EXE) (9.7.5.29616)
PATCH-317727Foxit PhantomPDF 9 (ML) (EXE) (9.7.5.29616)
PATCH-317728Foxit PhantomPDF 9 (ML) (MSI) (9.7.5.29616)
PATCH-317729Foxit PhantomPDF 9 (MSI) (9.7.5.29616)
PATCH-306313Foxit PhantomPDF (MSI) (8.3.2) (Formerly Foxit PhantomPDF Slim)
PATCH-347386Foxit Reader (2025.1.0.27937)
PATCH-347385Foxit PDF Reader (MSI) (2025.1.0.27937)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234