CVE-2020-12248: Foxitsoftware Phantompdf
High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can execute arbitrary code via a heap-based buffer overflow because dirty image-resource data is mishandled.
Affected products
- Foxitsoftware Phantompdf: up to and including 9.7.2.29539; up to and including 10.0.0.35798
- Foxitsoftware Reader: up to and including 10.0.0.35798
Published 2020-09-04. Last modified 2026-06-17.