Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-5556

EPSS 0.75% · P73
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2017-5556

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The ConvertToPDF plugin in Foxit Reader before 8.2 and PhantomPDF before 8.2 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG image. The vulnerability could lead to information disclosure; an attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
福昕Reader ConvertToPDF插件安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
福昕Reader on Windows是中国福昕(Foxit)软件公司的一款基于Windows平台PDF文档阅读器。Foxit PhantomPDF是一个商业版。ConvertToPDF是其中的一个PDF转换插件。 基于Windows平台的福昕Reader 8.1.4.1208及之前的版本和PhantomPDF 8.1.1.1115及之前的版本中的ConvertToPDF插件存在安全漏洞。远程攻击者可借助特制的JPEG图像利用该漏洞造成拒绝服务(越边界读取和应用程序崩溃),造成信息泄露。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2017-5556

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-5556

Please Login to view more intelligence information

Same Patch Batch · n/a · 2017-01-23 · 96 CVEs total

CVE-2016-7567OpenSLP 缓冲区错误漏洞
CVE-2016-7037Malcolm Fell jwt 安全漏洞
CVE-2016-6920FFmpeg 缓冲区错误漏洞
CVE-2016-6601ZOHO WebNMS Framework 路径遍历漏洞
CVE-2016-6600ZOHO WebNMS Framework 路径遍历漏洞
CVE-2016-6582Doorkeeper 安全漏洞
CVE-2016-6521Grails console 跨站请求伪造漏洞
CVE-2016-6517Liferay 路径遍历漏洞
CVE-2016-6602ZOHO WebNMS Framework 安全漏洞
CVE-2016-7410Libdwarf 安全漏洞
CVE-2016-7102ownCloud Desktop 代码注入漏洞
CVE-2016-7792Ubiquiti Networks UniFi 安全漏洞
CVE-2016-9012Arista Networks CloudVision Portal 安全漏洞
CVE-2016-9081Joomla! 安全漏洞
CVE-2016-9379Xen pygrub boot loader模拟器权限许可和访问控制漏洞
CVE-2016-9380Xen pygrub boot loader模拟器安全漏洞
CVE-2016-9381QEMU 竞争条件问题漏洞
CVE-2016-9382Xen 安全漏洞
CVE-2016-9383Xen 安全漏洞
CVE-2016-9385Xen 安全漏洞

Showing top 20 of 96 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2017-5556

No comments yet


Leave a comment