CVE-2018-19342

Description

The u3d plugin 9.3.0.10809 (aka pluginsU3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a Read Access Violation starting at U3DBrowser+0x000000000000347a issue.

Risk Information

Base Score
7.1
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
EPSS Score
Exploitation Probability
0.139

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Foxit Reader 9.3.0.10826Windows
Multiple Vulnerabilities are affected in Foxit Reader Enterprise 9.3.0.10826Windows
Multiple vulnerabilities are fixed in Foxit Reader (9.4.1.16828)Windows
Multiple vulnerabilities are fixed in Foxit Reader Enterprise (9.4.1.16828)Windows
Multiple vulnerabilities are fixed in Foxit Reader (9.4.0)Windows
Multiple vulnerabilities are fixed in Foxit Reader Enterprise (9.4.0)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-341796Foxit Reader (2024.3.0.26795)
PATCH-341798Foxit PDF Reader (MSI) (2024.3.0.26795) (Formerly Foxit Reader Enterprise)
PATCH-347386Foxit Reader (2025.1.0.27937)
PATCH-347385Foxit PDF Reader (MSI) (2025.1.0.27937)
PATCH-347386Foxit Reader (2025.1.0.27937)
PATCH-347385Foxit PDF Reader (MSI) (2025.1.0.27937)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234