CVE-2016-4064: Foxitsoftware Foxit Reader
High severity, CVSS 7.8. EPSS: 4.2% chance of exploitation in the next 30 days.
Use-after-free vulnerability in the XFA forms handling functionality in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via a crafted remerge call.
Affected products
- Foxitsoftware Foxit Reader: up to and including 7.3.0.118
- Foxitsoftware Phantompdf: up to and including 7.3.0.118
Published 2016-04-22. Last modified 2026-06-17.