CVE-2020-12247: Foxitsoftware Phantompdf
High severity, CVSS 7.1. EPSS: 3.6% chance of exploitation in the next 30 days.
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information from an out-of-bounds read because a text-string index continues to be used after splitting a string into two parts. A crash may also occur.
Affected products
- Foxitsoftware Phantompdf: up to and including 9.7.2.29539; up to and including 10.0.0.35798
- Foxitsoftware Reader: up to and including 10.0.0.35798
Published 2020-09-04. Last modified 2026-06-17.