High severity8.8NVD Advisory· Published Apr 23, 2018· Updated Jun 17, 2026
CVE-2018-3850
CVE-2018-3850
Description
An exploitable use-after-free vulnerability exists in the JavaScript engine Foxit Software Foxit PDF Reader version 9.0.1.1049. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If a browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: =9.0.1.1049
- Talos/Foxitv5Range: Foxit PDF Reader 9.0.1.1049.
Patches
Vulnerability mechanics
References
3- www.securityfocus.com/bid/103942nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1040733nvdThird Party AdvisoryVDB Entry
- www.talosintelligence.com/vulnerability_reports/TALOS-2018-0532nvdThird Party Advisory
News mentions
0No linked articles in our index yet.