Back to search
CVE-2010-20010
Published: Aug 20, 2025
Modified: May 15, 2026
PUBLISHED
Description
Foxit PDF Reader before 4.2.0.0928 does not properly bound-check the /Title entry in the PDF Info dictionary. A specially crafted PDF with an overlong Title string can overflow a fixed-size stack buffer, corrupt the Structured Exception Handler (SEH) chain, and lead to arbitrary code execution in the context of the user who opens the file.
| Vendor | Product | Versions |
|---|---|---|
Foxit Software | Foxit PDF Reader | affected 0 - < 4.2.0.0928 |
Weaknesses (CWE)
References
https://www.foxit.com/pdf-reader/version-history.html
vendor-advisory
patch
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now