foxitsoftware quick-pdf-library CVE-2018-20248 is a vulnerability in Foxit Software Quick Pdf Library
Published on December 24, 2018

In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing invalid xref table pointers or invalid xref table data using the LoadFromFile, LoadFromString, LoadFromStream, DAOpenFile or DAOpenFileReadOnly functions may result in an access violation caused by out of bounds memory access.

NVD

Weakness Type

What is a Memory Corruption Vulnerability?

The software writes data past the end, or before the beginning, of the intended buffer. Typically, this can result in corruption of data, a crash, or code execution. The software may modify an index or perform pointer arithmetic that references a memory location that is outside of the boundaries of the buffer. A subsequent write operation then produces undefined or unexpected results.

CVE-2018-20248 has been classified to as a Memory Corruption vulnerability or weakness.


Products Associated with CVE-2018-20248

Want to know whenever a new CVE is published for Foxit Software Quick Pdf Library? stack.watch will email you.

 

Exploit Probability

EPSS
0.15%
Percentile
34.56%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.