CVE-2019-5005: Foxitsoftware Foxit Reader
Medium severity, CVSS 5.5. EPSS: 1.3% chance of exploitation in the next 30 days.
An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. They allowed Denial of Service (application crash) via image data, because two bytes are written to the end of the allocated memory without judging whether this will cause corruption.
Affected products
- Foxitsoftware Foxit Reader: before 9.4 (fixed in 9.4)
- Foxitsoftware Phantompdf: before 9.4 (fixed in 9.4)
Published 2019-01-03. Last modified 2026-06-17.