CVE-2018-18933
9.1
CRITICAL · CVSS 3.0 · EPSS 3% (pctl 87)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Read Access Violation near NULL starting at FoxitReader!safe_vsnprintf+0x00000000002c4330" issue.
Scoring
| CVSS | 9.1 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
| EPSS | 3.01% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-125 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-11-05 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| foxitsoftware | foxit reader |
| foxitsoftware | u3d |
References
- https://github.com/Yan-1-20/Yan-1-20.github.io/blob/master/2018/11/02/2018/11/2018-11-02/index.html
- https://github.com/Yan-1-20/Yan-1-20.github.io/blob/master/2018/11/10/2018/11/2018-11-10/index.html
- https://yan-1-20.github.io/2018/11/02/2018/11/2018-11-02/
- https://yan-1-20.github.io/2018/11/10/2018/11/2018-11-10/
- https://www.foxitsoftware.com/support/security-bulletins.php
- https://github.com/Yan-1-20/Yan-1-20.github.io/blob/master/2018/11/02/2018/11/2018-11-02/index.html
- https://github.com/Yan-1-20/Yan-1-20.github.io/blob/master/2018/11/10/2018/11/2018-11-10/index.html
- https://yan-1-20.github.io/2018/11/02/2018/11/2018-11-02/
- https://yan-1-20.github.io/2018/11/10/2018/11/2018-11-10/
→ the Explorer · watch your stack · NVD