cvelist/2018/14xxx/CVE-2018-14267.json

67 lines
2.5 KiB
JSON
Raw Normal View History

2018-07-16 10:04:02 -04:00
{
2019-03-18 05:06:31 +00:00
"CVE_data_meta": {
"ASSIGNER": "zdi-disclosures@trendmicro.com",
"ID": "CVE-2018-14267",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Foxit Reader",
"version": {
"version_data": [
{
"version_value": "9.0.1.1049"
}
]
}
}
]
},
"vendor_name": "Foxit"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
ZDI assigns the following CVEs: M 2018/11xxx/CVE-2018-11617.json M 2018/11xxx/CVE-2018-11618.json M 2018/11xxx/CVE-2018-11619.json M 2018/11xxx/CVE-2018-11620.json M 2018/11xxx/CVE-2018-11621.json M 2018/11xxx/CVE-2018-11622.json M 2018/11xxx/CVE-2018-11623.json M 2018/14xxx/CVE-2018-14241.json M 2018/14xxx/CVE-2018-14242.json M 2018/14xxx/CVE-2018-14243.json M 2018/14xxx/CVE-2018-14244.json M 2018/14xxx/CVE-2018-14245.json M 2018/14xxx/CVE-2018-14246.json M 2018/14xxx/CVE-2018-14247.json M 2018/14xxx/CVE-2018-14248.json M 2018/14xxx/CVE-2018-14249.json M 2018/14xxx/CVE-2018-14250.json M 2018/14xxx/CVE-2018-14251.json M 2018/14xxx/CVE-2018-14252.json M 2018/14xxx/CVE-2018-14253.json M 2018/14xxx/CVE-2018-14254.json M 2018/14xxx/CVE-2018-14255.json M 2018/14xxx/CVE-2018-14256.json M 2018/14xxx/CVE-2018-14257.json M 2018/14xxx/CVE-2018-14258.json M 2018/14xxx/CVE-2018-14259.json M 2018/14xxx/CVE-2018-14260.json M 2018/14xxx/CVE-2018-14261.json M 2018/14xxx/CVE-2018-14262.json M 2018/14xxx/CVE-2018-14263.json M 2018/14xxx/CVE-2018-14264.json M 2018/14xxx/CVE-2018-14265.json M 2018/14xxx/CVE-2018-14266.json M 2018/14xxx/CVE-2018-14267.json M 2018/14xxx/CVE-2018-14268.json M 2018/14xxx/CVE-2018-14269.json M 2018/14xxx/CVE-2018-14270.json M 2018/14xxx/CVE-2018-14271.json M 2018/14xxx/CVE-2018-14272.json M 2018/14xxx/CVE-2018-14273.json M 2018/14xxx/CVE-2018-14274.json M 2018/14xxx/CVE-2018-14275.json M 2018/14xxx/CVE-2018-14276.json M 2018/14xxx/CVE-2018-14277.json M 2018/14xxx/CVE-2018-14278.json M 2018/14xxx/CVE-2018-14279.json M 2018/14xxx/CVE-2018-14280.json M 2018/14xxx/CVE-2018-14281.json M 2018/14xxx/CVE-2018-14282.json M 2018/14xxx/CVE-2018-14283.json M 2018/14xxx/CVE-2018-14284.json M 2018/14xxx/CVE-2018-14285.json M 2018/14xxx/CVE-2018-14286.json M 2018/14xxx/CVE-2018-14287.json M 2018/14xxx/CVE-2018-14288.json M 2018/14xxx/CVE-2018-14289.json M 2018/14xxx/CVE-2018-14290.json M 2018/14xxx/CVE-2018-14291.json M 2018/14xxx/CVE-2018-14292.json M 2018/14xxx/CVE-2018-14293.json M 2018/14xxx/CVE-2018-14294.json M 2018/14xxx/CVE-2018-14295.json M 2018/14xxx/CVE-2018-14296.json M 2018/14xxx/CVE-2018-14297.json M 2018/14xxx/CVE-2018-14298.json M 2018/14xxx/CVE-2018-14299.json M 2018/14xxx/CVE-2018-14300.json M 2018/14xxx/CVE-2018-14301.json M 2018/14xxx/CVE-2018-14302.json M 2018/14xxx/CVE-2018-14303.json M 2018/14xxx/CVE-2018-14304.json M 2018/14xxx/CVE-2018-14305.json M 2018/14xxx/CVE-2018-14306.json M 2018/14xxx/CVE-2018-14307.json M 2018/14xxx/CVE-2018-14308.json M 2018/14xxx/CVE-2018-14309.json M 2018/14xxx/CVE-2018-14310.json M 2018/14xxx/CVE-2018-14311.json M 2018/14xxx/CVE-2018-14312.json M 2018/14xxx/CVE-2018-14313.json M 2018/14xxx/CVE-2018-14314.json M 2018/14xxx/CVE-2018-14315.json M 2018/14xxx/CVE-2018-14316.json
2018-07-31 13:38:38 -05:00
{
2019-03-18 05:06:31 +00:00
"lang": "eng",
"value": "This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the importTextData method. By performing actions in JavaScript, an attacker can trigger a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-6030."
ZDI assigns the following CVEs: M 2018/11xxx/CVE-2018-11617.json M 2018/11xxx/CVE-2018-11618.json M 2018/11xxx/CVE-2018-11619.json M 2018/11xxx/CVE-2018-11620.json M 2018/11xxx/CVE-2018-11621.json M 2018/11xxx/CVE-2018-11622.json M 2018/11xxx/CVE-2018-11623.json M 2018/14xxx/CVE-2018-14241.json M 2018/14xxx/CVE-2018-14242.json M 2018/14xxx/CVE-2018-14243.json M 2018/14xxx/CVE-2018-14244.json M 2018/14xxx/CVE-2018-14245.json M 2018/14xxx/CVE-2018-14246.json M 2018/14xxx/CVE-2018-14247.json M 2018/14xxx/CVE-2018-14248.json M 2018/14xxx/CVE-2018-14249.json M 2018/14xxx/CVE-2018-14250.json M 2018/14xxx/CVE-2018-14251.json M 2018/14xxx/CVE-2018-14252.json M 2018/14xxx/CVE-2018-14253.json M 2018/14xxx/CVE-2018-14254.json M 2018/14xxx/CVE-2018-14255.json M 2018/14xxx/CVE-2018-14256.json M 2018/14xxx/CVE-2018-14257.json M 2018/14xxx/CVE-2018-14258.json M 2018/14xxx/CVE-2018-14259.json M 2018/14xxx/CVE-2018-14260.json M 2018/14xxx/CVE-2018-14261.json M 2018/14xxx/CVE-2018-14262.json M 2018/14xxx/CVE-2018-14263.json M 2018/14xxx/CVE-2018-14264.json M 2018/14xxx/CVE-2018-14265.json M 2018/14xxx/CVE-2018-14266.json M 2018/14xxx/CVE-2018-14267.json M 2018/14xxx/CVE-2018-14268.json M 2018/14xxx/CVE-2018-14269.json M 2018/14xxx/CVE-2018-14270.json M 2018/14xxx/CVE-2018-14271.json M 2018/14xxx/CVE-2018-14272.json M 2018/14xxx/CVE-2018-14273.json M 2018/14xxx/CVE-2018-14274.json M 2018/14xxx/CVE-2018-14275.json M 2018/14xxx/CVE-2018-14276.json M 2018/14xxx/CVE-2018-14277.json M 2018/14xxx/CVE-2018-14278.json M 2018/14xxx/CVE-2018-14279.json M 2018/14xxx/CVE-2018-14280.json M 2018/14xxx/CVE-2018-14281.json M 2018/14xxx/CVE-2018-14282.json M 2018/14xxx/CVE-2018-14283.json M 2018/14xxx/CVE-2018-14284.json M 2018/14xxx/CVE-2018-14285.json M 2018/14xxx/CVE-2018-14286.json M 2018/14xxx/CVE-2018-14287.json M 2018/14xxx/CVE-2018-14288.json M 2018/14xxx/CVE-2018-14289.json M 2018/14xxx/CVE-2018-14290.json M 2018/14xxx/CVE-2018-14291.json M 2018/14xxx/CVE-2018-14292.json M 2018/14xxx/CVE-2018-14293.json M 2018/14xxx/CVE-2018-14294.json M 2018/14xxx/CVE-2018-14295.json M 2018/14xxx/CVE-2018-14296.json M 2018/14xxx/CVE-2018-14297.json M 2018/14xxx/CVE-2018-14298.json M 2018/14xxx/CVE-2018-14299.json M 2018/14xxx/CVE-2018-14300.json M 2018/14xxx/CVE-2018-14301.json M 2018/14xxx/CVE-2018-14302.json M 2018/14xxx/CVE-2018-14303.json M 2018/14xxx/CVE-2018-14304.json M 2018/14xxx/CVE-2018-14305.json M 2018/14xxx/CVE-2018-14306.json M 2018/14xxx/CVE-2018-14307.json M 2018/14xxx/CVE-2018-14308.json M 2018/14xxx/CVE-2018-14309.json M 2018/14xxx/CVE-2018-14310.json M 2018/14xxx/CVE-2018-14311.json M 2018/14xxx/CVE-2018-14312.json M 2018/14xxx/CVE-2018-14313.json M 2018/14xxx/CVE-2018-14314.json M 2018/14xxx/CVE-2018-14315.json M 2018/14xxx/CVE-2018-14316.json
2018-07-31 13:38:38 -05:00
}
2019-03-18 05:06:31 +00:00
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-843-Access of Resource Using Incompatible Type ('Type Confusion')"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://www.foxitsoftware.com/support/security-bulletins.php",
"refsource": "CONFIRM",
"url": "https://www.foxitsoftware.com/support/security-bulletins.php"
},
{
"name": "https://zerodayinitiative.com/advisories/ZDI-18-727",
"refsource": "MISC",
"url": "https://zerodayinitiative.com/advisories/ZDI-18-727"
}
]
}
}