CVE-2020-28203: Foxitsoftware Foxit Reader

Medium severity, CVSS 5.5. EPSS: 1.9% chance of exploitation in the next 30 days.

An issue was discovered in Foxit Reader and PhantomPDF 10.1.0.37527 and earlier. There is a null pointer access/dereference while opening a crafted PDF file, leading the application to crash (denial of service).

Affected products

  • Foxitsoftware Foxit Reader: before 10.1.0.37527 (fixed in 10.1.0.37527)
  • Foxitsoftware Phantompdf: before 10.1.0.37527 (fixed in 10.1.0.37527)

Published 2020-12-15. Last modified 2026-06-17.