CVE-2018-17781: Foxitsoftware Phantompdf

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

Foxit PhantomPDF and Reader before 9.3 allow remote attackers to trigger Uninitialized Object Information Disclosure because creation of ArrayBuffer and DataView objects is mishandled.

Affected products

Published 2018-09-29. Last modified 2026-06-17.