« Volver al listado

CVE-2014-8074

Estado: ModificadaMedia (6.8)—

Buffer overflow in the SetLogFile method in Foxit.FoxitPDFSDKProCtrl.5 in Foxit PDF SDK ActiveX 2.3 through 5.0.1820 before 5.0.2.924 allows remote attackers to execute arbitrary code via a long string, related to global variables.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-8074",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-10-17T15:55:07.227",
  "references": [
    {
      "url": "http://www.foxitsoftware.com/support/security_bulletins.php#FRD-22",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/70608",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.zerodayinitiative.com/advisories/ZDI-14-362/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.foxitsoftware.com/support/security_bulletins.php#FRD-22",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/70608",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.zerodayinitiative.com/advisories/ZDI-14-362/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Buffer overflow in the SetLogFile method in Foxit.FoxitPDFSDKProCtrl.5 in Foxit PDF SDK ActiveX 2.3 through 5.0.1820 before 5.0.2.924 allows remote attackers to execute arbitrary code via a long string, related to global variables."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de buffer en el método SetLogFile en Foxit.FoxitPDFSDKProCtrl.5 de Foxit PDF SDK ActiveX 2.3 hasta 5.0.1820 anteriores a 5.0.2.924 permite a atacantes remotos ejecutar código arbitrario a través de una larga cadena, relacionado con variables globales."
    }
  ],
  "lastModified": "2026-06-17T00:16:11.003",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_pdf_sdk_activex:2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D028D2A-E5B0-4A9E-98F4-B2D5A27E0228"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_pdf_sdk_activex:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7BB1C090-E505-4EDF-AF03-6876A41323B8"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_pdf_sdk_activex:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B1D8EF06-CF69-4BA7-946C-18731A55EE1D"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_pdf_sdk_activex:5.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F384A455-7EEF-4E26-9923-2B411A6D0572"
            },
            {
              "criteria": "cpe:2.3:a:foxitsoftware:foxit_pdf_sdk_activex:5.0.1.820:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "56E14171-24CC-4D3C-A382-E761728CEE27"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}