CVE-2015-3632
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 6.1%
from disclosure to weapon0 days
Published on NVDMay 1
1st PoCApr 29
exploitation probability
6.1%top 7% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted GIF in a PDF file.
Affected products
n/a · n/apublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/36859unverifiedcve_referencepacketstormsecurity.com/files/131685/Foxit-Reader-7.1.3.320-Memory-Corruption.htmlunverifiedcve_referencewww.exploit-db.com/exploits/36859/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/131685/Foxit-Reader-7.1.3.320-Memory-Corruption.htmlhttp://protekresearchlab.com/PRL-2015-05/https://www.exploit-db.com/exploits/36859/http://www.foxitsoftware.com/support/security_bulletins.php#FRD-27http://www.securityfocus.com/bid/74418http://www.securitytracker.com/id/1032229