foxitsoftware foxit-reader CVE-2020-13547 is a vulnerability in Foxit Software Foxit Reader
Published on December 22, 2020

A type confusion vulnerability exists in the JavaScript engine of Foxit Softwares Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger an improper use of an object, resulting in memory corruption and arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

NVD

Weakness Type

What is an Object Type Confusion Vulnerability?

The program allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

CVE-2020-13547 has been classified to as an Object Type Confusion vulnerability or weakness.


Products Associated with CVE-2020-13547

Want to know whenever a new CVE is published for Foxit Software Foxit Reader? stack.watch will email you.

 

Exploit Probability

EPSS
1.02%
Percentile
76.96%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.