CVE-2019-5005: Foxitsoftware Foxit Reader

Medium severity, CVSS 5.5. EPSS: 1.3% chance of exploitation in the next 30 days.

An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. They allowed Denial of Service (application crash) via image data, because two bytes are written to the end of the allocated memory without judging whether this will cause corruption.

Affected products

Published 2019-01-03. Last modified 2026-06-17.