Foxit Pdf Reader vulnerabilities

8 known vulnerabilities affecting foxit/foxit_pdf_reader.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH8

Vulnerabilities

Page 1 of 1
CVE-2018-3957HIGHCVSS 7.8vFoxit Software Foxit PDF Reader 9.1.0.5096.2018-10-02
CVE-2018-3957 [HIGH] CWE-416 CVE-2018-3957: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Keywords property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled,
cvelistv5nvd
CVE-2018-3944HIGHCVSS 8.8vFoxit Software Foxit PDF Reader 9.1.0.5096.2018-10-02
CVE-2018-3944 [HIGH] CWE-416 CVE-2018-3944: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability.
cvelistv5nvd
CVE-2018-3959HIGHCVSS 7.8vFoxit Software Foxit PDF Reader 9.1.0.5096.2018-10-02
CVE-2018-3959 [HIGH] CWE-416 CVE-2018-3959: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Author property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, v
cvelistv5nvd
CVE-2018-3943HIGHCVSS 8.8vFoxit Software PDF Reader 9.1.0.5096.2018-10-02
CVE-2018-3943 [HIGH] CWE-416 CVE-2018-3943: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability.
cvelistv5nvd
CVE-2018-3958HIGHCVSS 7.8vFoxit Software Foxit PDF Reader 9.1.0.5096.2018-10-02
CVE-2018-3958 [HIGH] CWE-416 CVE-2018-3958: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Subject property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled,
cvelistv5nvd
CVE-2018-3961HIGHCVSS 7.8vFoxit Software Foxit PDF Reader 9.1.0.5096.2018-10-02
CVE-2018-3961 [HIGH] CWE-416 CVE-2018-3961: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Creator property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled,
cvelistv5nvd
CVE-2018-3962HIGHCVSS 7.3vFoxit Software Foxit PDF Reader 9.1.0.5096.2018-10-02
CVE-2018-3962 [HIGH] CWE-416 CVE-2018-3962: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the CreationDate property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enab
cvelistv5nvd
CVE-2018-3960HIGHCVSS 7.8vFoxit Software Foxit PDF Reader 9.1.0.5096.2018-10-02
CVE-2018-3960 [HIGH] CWE-416 CVE-2018-3960: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Producer property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled,
cvelistv5nvd