CVE-2019-5007: Foxitsoftware Foxit Reader
High severity, CVSS 7.1. EPSS: 1.6% chance of exploitation in the next 30 days.
An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. It is an Out-of-Bounds Read Information Disclosure and crash due to a NULL pointer dereference when reading TIFF data during TIFF parsing.
Affected products
- Foxitsoftware Foxit Reader: before 9.4 (fixed in 9.4)
- Foxitsoftware Phantompdf: before 9.4 (fixed in 9.4)
Published 2019-01-03. Last modified 2026-06-17.