Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Foxit Reader before 10.1.1 (and before 4.1.1 on macOS) and PhantomPDF before 9.7.5 and 10.x before 10.1.1 (and before 4.1.1 on macOS). An attacker can spoof a certified PDF document via an Evil Annotation Attack because the products fail to consider a null value for a Subtype entry of the Annotation dictionary, in an incremental update.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Foxit Reader和Foxit PhantomPDF 代码问题漏洞
Vulnerability Description
Foxit Reader和Foxit PhantomPDF都是中国福昕(Foxit)公司的一款PDF文档阅读器。 Foxit Reader 和 PhantomPDF 存在安全漏洞,攻击者可利用该漏洞可以通过恶意注释攻击来欺骗认证的PDF文档,因为在增量更新时,产品没有考虑到注释字典的子类型条目的空值。以下产品及版本受到影响: Foxit Reader before 10.1.1 (and before 4.1.1 on macOS) and PhantomPDF before 9.7.5 and 10.x
CVSS Information
N/A
Vulnerability Type
N/A