Vulnerabilities > CVE-2020-13806 - Use After Free vulnerability in Foxitsoftware Reader

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
foxitsoftware
CWE-416

Summary

An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has a use-after-free because of JavaScript execution after a deletion or close operation.

Vulnerable Configurations

Part Description Count
Application
Foxitsoftware
219

Common Weakness Enumeration (CWE)