Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2018-3924 Details

Description

An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0588 CVEExploitTechnical DescriptionThird Party Advisory
http://www.securitytracker.com/id/1041353 CVEThird Party AdvisoryVDB Entry
https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0588 [email protected]ExploitTechnical DescriptionThird Party Advisory
http://www.securitytracker.com/id/1041353 [email protected]Third Party AdvisoryVDB Entry

Weakness Enumeration

CWE-IDCWE NameSource
CWE-416Use After Free[email protected]

Affected Products

ProductVersions
foxitsoftware foxit reader
<= 9.1.0.5096

CPE

  • cpe:2.3:a:foxitsoftware:foxit_reader:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
foxitsoftware phantompdf
<= 9.1.0.5096

CPE

  • cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
microsoft windows
All versions

CPE

  • cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

6 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2018-3924
NVD Published Date:
Aug 1, 2018
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]