AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-3956

HIGH · CVSS 7.1 EPSS 49.57% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-01-30 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2018-3956
Severity
HIGH
CVSS
7.1
EPSS
49.57%

Original NVD Description

An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Software's PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger an out-of-bounds read, which can disclose sensitive memory content and aid in exploitation when coupled with another vulnerability. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.