VYPR
High severity8.1NVD Advisory· Published Sep 4, 2020· Updated Jun 17, 2026

CVE-2020-11493

CVE-2020-11493

Description

In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to Stream without concern for a crafted XObject.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:*range: <=9.7.2.29539
    • (no CPE)range: <10.0.1, <9.7.3
  • cpe:2.3:a:foxitsoftware:reader:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:foxitsoftware:reader:*:*:*:*:*:*:*:*range: <=10.0.0.35798
    • (no CPE)range: <10.0.1
  • Foxit/Foxit Readerdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.