High severity8.8NVD Advisory· Published Oct 31, 2016· Updated May 6, 2026
CVE-2016-8878
CVE-2016-8878
Description
Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute arbitrary code via a crafted BMP image embedded in the XFA stream in a PDF document, aka "Data from Faulting Address may be used as a return value starting at FOXITREADER."
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.foxitsoftware.com/support/security-bulletins.phpnvdPatchVendor Advisory
- www.securityfocus.com/bid/93608nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.