High severity7.8NVD Advisory· Published Dec 31, 2020· Updated Jun 17, 2026
CVE-2020-35931
CVE-2020-35931
Description
An issue was discovered in Foxit Reader before 10.1.1 (and before 4.1.1 on macOS) and PhantomPDF before 9.7.5 and 10.x before 10.1.1 (and before 4.1.1 on macOS). An attacker can spoof a certified PDF document via an Evil Annotation Attack because the products fail to consider a null value for a Subtype entry of the Annotation dictionary, in an incremental update.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Foxit/Readerdescription
<9.7.5, <10.1.1, <4.1.1 on macOS+ 1 more
- (no CPE)range: <9.7.5, <10.1.1, <4.1.1 on macOS
- cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:*range: <9.7.5
<10.1.1, <4.1.1 on macOS+ 1 more
- (no CPE)range: <10.1.1, <4.1.1 on macOS
- cpe:2.3:a:foxitsoftware:foxit_reader:*:*:*:*:*:*:*:*range: <10.1.1
Patches
Vulnerability mechanics
References
1- www.foxitsoftware.com/support/security-bulletins.htmlnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.