CVE-2021-40326
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/08/2022
Last modified:
02/09/2022
Description
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An attacker can write to an arbitrary file, and display controlled contents, during signature verification.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* | 11.0 (including) | 11.1 (excluding) |
| cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:* | 11.0 (including) | 11.1 (excluding) |
| cpe:2.3:a:foxit:phantompdf:*:*:*:*:*:*:*:* | 10.1.6 (excluding) | |
| cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



