← Vulnerability feed

Vulnerability record · CVE-2018-3956 · published 30 January 2019

CVE-2018-3956: Foxit PDF Reader XFA attribute out-of-bounds read

Foxitsoftware · Phantompdf

Foxit Software's PDF Reader 9.1.0.5096 mishandles certain XFA element attributes, causing an out-of-bounds read. A crafted PDF can leak sensitive memory contents, which aids exploitation when chained with another flaw. The record names only version 9.1.0.5096, so other versions cannot be confirmed as affected or fixed from the data given.

7.1 CVSS 3.1 High EPSS 46% · top 1.2% CWE-125 · Out-of-bounds read
7.1CVSS 3.1 base score, v2 5.8
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Software's PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger an out-of-bounds read, which can disclose sensitive memory content and aid in exploitation when coupled with another vulnerability. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityHigh CVSS (7.1) with a public exploit reference and very high EPSS percentile, though it requires user interaction and only leaks memory.

What it is

Foxit Software's PDF Reader 9.1.0.5096 mishandles certain XFA element attributes, causing an out-of-bounds read. A crafted PDF can leak sensitive memory contents, which aids exploitation when chained with another flaw. The record names only version 9.1.0.5096, so other versions cannot be confirmed as affected or fixed from the data given.

Impact

An attacker gains disclosure of memory contents from the reader process, which can expose sensitive data and provide information useful for a follow-on exploit. The out-of-bounds read alone does not give code execution.

Attack surface

Reached by opening a malicious PDF, requiring user interaction to trick the victim into opening the file; if the browser plugin extension is enabled, visiting a malicious site can also trigger it. No authentication or privileges are needed (PR:N, UI:R, AV:L).

Exploitation

Not listed in CISA KEV, but EPSS is 0.46008 (98.75th percentile), indicating elevated predicted exploitation activity. Both references are tagged Exploit and Third Party Advisory, so public exploit detail exists.

What to do

  • Update Foxit Reader and PhantomPDF to a version later than 9.1.0.5096; the record does not state the fixed version, so confirm with the vendor advisory.
  • Disable or remove the browser plugin extension to close the drive-by path.
  • Block or sandbox untrusted PDF attachments and downloads at the mail and web gateway.
  • Restrict PDF handling to a hardened or isolated viewer for untrusted documents.
  • Monitor Foxit vendor advisories for the patched release and track deployment.

Detection

  • Hunt for Foxit Reader or PhantomPDF crashes or abnormal exits tied to XFA-heavy PDFs.
  • Alert on PDFs containing XFA element attributes from untrusted sources reaching endpoints.
  • Correlate process-level memory read anomalies or exploit-protection events in the reader process.
  • Track reader version inventory to find hosts still on 9.1.0.5096.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-3956 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-0836Foxitsoftware reader memory buffer overflow vulnerabilityFoxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing dangerous…EPSS 41%9.8CVE-2021-38574Foxitsoftware foxit reader sql injection vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.EPSS 0.99%9.8CVE-2021-38568Foxitsoftware foxit reader out-of-bounds write vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows memory corruption during conversion of a PDF document to a different …EPSS 1.1%9.8CVE-2021-38572Foxitsoftware foxit reader vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because the extractPages pathname is not v…EPSS 1.1%9.8CVE-2021-38573Foxitsoftware foxit reader vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not val…EPSS 1.1%9.8CVE-2021-33793Foxitsoftware foxit reader out-of-bounds write vulnerabilityFoxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write because the Cross-Reference table is mishandled during Office doc…EPSS 1.1%9.8CVE-2020-26534Foxitsoftware foxit reader use after free vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Field::ClearItems and Field::Del…EPSS 2.4%9.8CVE-2020-26535Foxitsoftware foxit reader out-of-bounds write vulnerabilityAn issue was discovered in Foxit Reader and PhantomPDF before 10.1. If TslAlloc attempts to allocate thread local storage but obtains an unacceptable…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2018-3956), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.