CVE-2018-19347

Description

The u3d plugin 9.3.0.10809 (aka pluginsU3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a Data from Faulting Address controls Branch Selection starting at U3DBrowser!PlugInMain+0x00000000000d11bb issue.

Risk Information

Base Score
7.1
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
EPSS Score
Exploitation Probability
0.071

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Foxit Reader 9.3.0.10826Windows
Multiple Vulnerabilities are affected in Foxit Reader Enterprise 9.3.0.10826Windows
Multiple vulnerabilities are fixed in Foxit Reader (9.4.1.16828)Windows
Multiple vulnerabilities are fixed in Foxit Reader Enterprise (9.4.1.16828)Windows
Multiple vulnerabilities are fixed in Foxit Reader (9.4.0)Windows
Multiple vulnerabilities are fixed in Foxit Reader Enterprise (9.4.0)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-341796Foxit Reader (2024.3.0.26795)
PATCH-341798Foxit PDF Reader (MSI) (2024.3.0.26795) (Formerly Foxit Reader Enterprise)
PATCH-347386Foxit Reader (2025.1.0.27937)
PATCH-347385Foxit PDF Reader (MSI) (2025.1.0.27937)
PATCH-347386Foxit Reader (2025.1.0.27937)
PATCH-347385Foxit PDF Reader (MSI) (2025.1.0.27937)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234