← Vulnerability feed

Vulnerability record · CVE-2009-0837 · published 10 March 2009

CVE-2009-0837: Foxit Reader stack buffer overflow via long filename path in action

Foxit · Reader3.0

Foxit Reader 3.0 before Build 1506 (including 1120 and 1301) contains a stack-based buffer overflow when processing a long relative or absolute path in the filename argument of an action, such as the 'Open/Execute a file' action. A crafted PDF can trigger the overflow and corrupt the stack, which matters because the reader is a common document viewer and the flaw is remotely reachable.

10.0 CVSS 2.0 High EPSS 76% · top 0.5% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to execute arbitrary code via a long (1) relative path or (2) absolute path in the filename argument in an action, as demonstrated by the "Open/Execute a file" action.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw allows remote code execution with no authentication and has a very high EPSS score, though it is not in KEV and affects an old, likely replaced version.

What it is

Foxit Reader 3.0 before Build 1506 (including 1120 and 1301) contains a stack-based buffer overflow when processing a long relative or absolute path in the filename argument of an action, such as the 'Open/Execute a file' action. A crafted PDF can trigger the overflow and corrupt the stack, which matters because the reader is a common document viewer and the flaw is remotely reachable.

Impact

An attacker can execute arbitrary code in the context of the user running Foxit Reader. Because the CVSS vector rates confidentiality, integrity and availability as complete, a successful exploit can fully compromise the host process and potentially the user's session.

Attack surface

The flaw is reached remotely over the network when a user opens a malicious PDF containing a crafted action with an oversized filename path. No authentication is required, but user interaction (opening the document) is implied by the vector and the reader context.

Exploitation

The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.75781, 99.5th percentile), indicating a strong likelihood of exploitation activity. References are vendor advisories and third-party write-ups rather than public exploit code tags.

What to do

  • Upgrade Foxit Reader to Build 1506 or later, or to a currently supported release.
  • If upgrade is not possible, disable or restrict the 'Open/Execute a file' action and other action handling in Foxit Reader policy settings.
  • Block untrusted PDFs at email and web gateways, and enforce attachment filtering for PDFs from external sources.
  • Run Foxit Reader with least privilege and enable OS-level exploit mitigations (DEP, ASLR) where available.
  • Consider an alternative hardened PDF reader for high-risk users until the affected version is removed.

Detection

  • Monitor for Foxit Reader process crashes or abnormal terminations, especially when opening PDFs from email or web downloads.
  • Search endpoint logs for child processes spawned by Foxit Reader, which may indicate successful exploitation of the 'Open/Execute a file' action.
  • Inspect PDFs for action objects containing unusually long filename paths, particularly relative or absolute paths in Open/Execute actions.
  • Correlate network downloads of PDFs with subsequent Foxit Reader execution and any unexpected process creation on the host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-0837 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed8.8CVE-2026-3910Google Chrome V8 improper implementation allows sandbox code executionChrome before 146.0.7680.75 contains an inappropriate implementation in the V8 JavaScript engine, classified as code injection and memory buffer over…KEVEPSS 1.0%analysed8.8CVE-2008-0015Microsoft DirectShow Video ActiveX Control Stack Buffer OverflowA stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequ…KEVEPSS 77%analysed7.8CVE-2026-20700Apple OS memory corruption allows arbitrary code executionA memory corruption flaw caused by improper state management affects iOS, iPadOS, macOS, tvOS, visionOS and watchOS. Apple states it is aware of a re…KEVEPSS 1.3%analysed8.8CVE-2025-14174Google Chrome ANGLE out-of-bounds memory access on MacChrome on macOS before 143.0.7499.110 contains an out-of-bounds memory access in the ANGLE graphics layer, classified as an out-of-bounds write (CWE-…KEVEPSS 22%analysed

Source: NIST National Vulnerability Database (record CVE-2009-0837), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.