CVE-2018-17610: Foxitsoftware Phantompdf
Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This relates to one of five distinct types of Annotation objects.
Affected products
- Foxitsoftware Phantompdf: before 9.3 (fixed in 9.3)
- Foxitsoftware Reader: before 9.3 (fixed in 9.3)
Published 2018-09-28. Last modified 2026-06-17.