VYPR
High severity7.8NVD Advisory· Published Dec 31, 2020· Updated Jun 17, 2026

CVE-2020-35931

CVE-2020-35931

Description

An issue was discovered in Foxit Reader before 10.1.1 (and before 4.1.1 on macOS) and PhantomPDF before 9.7.5 and 10.x before 10.1.1 (and before 4.1.1 on macOS). An attacker can spoof a certified PDF document via an Evil Annotation Attack because the products fail to consider a null value for a Subtype entry of the Annotation dictionary, in an incremental update.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Foxit/Readerdescription
  • Foxitsoftware/PhantomPDF Macllm-fuzzy2 versions
    <9.7.5, <10.1.1, <4.1.1 on macOS+ 1 more
    • (no CPE)range: <9.7.5, <10.1.1, <4.1.1 on macOS
    • cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:*range: <9.7.5
  • Foxitsoftware/Readerllm-fuzzy2 versions
    <10.1.1, <4.1.1 on macOS+ 1 more
    • (no CPE)range: <10.1.1, <4.1.1 on macOS
    • cpe:2.3:a:foxitsoftware:foxit_reader:*:*:*:*:*:*:*:*range: <10.1.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.