Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing dangerous actions defined in a PDF file, which allows remote attackers to execute arbitrary programs and have unspecified other impact via a crafted file, as demonstrated by the "Open/Execute a file" action.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T04:48:52.311Z
Reserved: 2009-03-06T00:00:00.000Z
Link: CVE-2009-0836
No data.
Status : Deferred
Published: 2009-03-10T20:30:06.577
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-0836
No data.
OpenCVE Enrichment
No data.
Weaknesses