Foxit PDF Reader before 4.2.0.0928 does not properly bound-check the /Title entry in the PDF Info dictionary. A specially crafted PDF with an overlong Title string can overflow a fixed-size stack buffer, corrupt the Structured Exception Handler (SEH) chain, and lead to arbitrary code execution in the context of the user who opens the file.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Aug 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Foxitsoftware
Foxitsoftware foxit Reader |
|
Vendors & Products |
Foxitsoftware
Foxitsoftware foxit Reader |
Wed, 20 Aug 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 20 Aug 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Foxit PDF Reader before 4.2.0.0928 does not properly bound-check the /Title entry in the PDF Info dictionary. A specially crafted PDF with an overlong Title string can overflow a fixed-size stack buffer, corrupt the Structured Exception Handler (SEH) chain, and lead to arbitrary code execution in the context of the user who opens the file. | |
Title | Foxit PDF Reader < 4.2.0.0928 Title Stack Buffer Overflow | |
Weaknesses | CWE-121 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-08-20T18:47:21.503Z
Reserved: 2025-08-19T16:00:37.416Z
Link: CVE-2010-20010

Updated: 2025-08-20T18:47:14.921Z

Status : Awaiting Analysis
Published: 2025-08-20T17:15:33.023
Modified: 2025-08-22T18:09:17.710
Link: CVE-2010-20010

No data.

Updated: 2025-08-21T12:58:57Z