CVE-2015-2790
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted (1) Ubyte Size in a DataSubBlock structure or (2) LZWMinimumCodeSize in a GIF image.
- Affected products
- Enterprise Reader, Foxit Reader, Phantompdf
- Foxitsoftware Enterprise Reader
- ≤ 7.0.6.1126
- Foxitsoftware Foxit Reader
- ≤ 7.0.6.1126
- Foxitsoftware Phantompdf
- ≤ 7.0.6.1126
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 24.5% (98th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2015-03-30
CVE-2015-2790 at NVD
2 known exploits for CVE-2015-2790
Proof-of-concept code and exploit modules indexed by Sploitus