peter bassill · operator
$ cve CVE-2018-18933 JSON

CVE-2018-18933

9.1
CRITICAL · CVSS 3.0 · EPSS 3% (pctl 87)

In your normal cycle

Critical by CVSS (9.1), but no sign of active exploitation.

Description

The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Read Access Violation near NULL starting at FoxitReader!safe_vsnprintf+0x00000000002c4330" issue.

Scoring

CVSS9.1 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS3.01% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-125
On CISA KEVno
Public exploitnone known
Published2018-11-05
Last modified2026-06-17

Affected (2)

VendorProduct
foxitsoftwarefoxit reader
foxitsoftwareu3d

References

→ the Explorer  ·  watch your stack  ·  NVD