AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2016-8875

MEDIUM · CVSS 5.3 EPSS 1.09%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2016-10-31 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2016-8875
Severity
MEDIUM
CVSS
5.3
EPSS
1.09%
Windows

Original Filing — NVD Description

The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image, aka "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at ConvertToPDF_x86!CreateFXPDFConvertor."