Description
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.4.37651. A specially crafted PDF document can trigger the reuse of previously free memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening a malicious file or site to trigger this vulnerability if the browser plugin extension is enabled.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-9041 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.4.37651. A specially crafted PDF document can trigger the reuse of previously free memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening a malicious file or site to trigger this vulnerability if the browser plugin extension is enabled. |
References
History
No history.
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2024-08-03T18:23:29.544Z
Reserved: 2021-01-04T00:00:00.000Z
Link: CVE-2021-21870
No data.
Status : Modified
Published: 2021-08-05T21:15:10.780
Modified: 2024-11-21T05:49:08.837
Link: CVE-2021-21870
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD