CVE-2009-0836

N/A Unknown
Published: March 10, 2009 Modified: April 23, 2026
View on NVD

Description

Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing dangerous actions defined in a PDF file, which allows remote attackers to execute arbitrary programs and have unspecified other impact via a crafted file, as demonstrated by the "Open/Execute a file" action.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/34036
Source: cve@mitre.org
Vendor Advisory
http://www.foxitsoftware.com/pdf/reader/security.htm#bypass
Source: cve@mitre.org
Patch Vendor Advisory
http://www.securityfocus.com/bid/34035
Source: cve@mitre.org
Vendor Advisory
http://www.vupen.com/english/advisories/2009/0634
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/34036
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.coresecurity.com/content/foxit-reader-vulnerabilities
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.foxitsoftware.com/pdf/reader/security.htm#bypass
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://www.securityfocus.com/archive/1/501623/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/34035
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.securitytracker.com/id?1021824
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2009/0634
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

18 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
10.8%
93th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

foxitsoftware