CVE-2020-12248: Foxitsoftware Phantompdf

High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.

In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can execute arbitrary code via a heap-based buffer overflow because dirty image-resource data is mishandled.

Affected products

  • Foxitsoftware Phantompdf: up to and including 9.7.2.29539; up to and including 10.0.0.35798
  • Foxitsoftware Reader: up to and including 10.0.0.35798

Published 2020-09-04. Last modified 2026-06-17.