cvedb.io
CVE-2018-20248
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2018-12-24T18:29:00.350 · Last modified 2026-06-17T01:52:33.757

Summary

In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing invalid xref table pointers or invalid xref table data using the LoadFromFile, LoadFromString, LoadFromStream, DAOpenFile or DAOpenFileReadOnly functions may result in an access violation caused by out of bounds memory access.

Affected products

foxitsoftware — quick_pdf_library

Does this affect you?

Add your gear to cvedb and we'll alert you only when foxitsoftware ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.