Foxit Reader vulnerabilities
247 known vulnerabilities affecting foxit/foxit_reader.
Total CVEs
247
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH197MEDIUM49
Vulnerabilities
Page 10 of 13
CVE-2024-49576P3HIGHCVSS 8.8v2024.3.0.267952024-12-18
CVE-2024-49576 [HIGH] CWE-416 CVE-2024-49576: A use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a checkbox CBF_
A use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a checkbox CBF_Widget object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious
nvd
CVE-2018-11622P3HIGHCVSS 8.8v9.0.1.10492018-07-31
CVE-2018-11622 [HIGH] CWE-787 CVE-2018-11622: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within ConvertToPDF_x86.dll. The issue results from the lack of proper v
nvd
CVE-2018-9982P3HIGHCVSS 8.8v9.0.0.299352018-05-17
CVE-2018-9982 [HIGH] CWE-787 CVE-2018-9982: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of the Texture Width in U3D files. The issue results f
nvd
CVE-2018-10473P3HIGHCVSS 8.8v9.0.0.299352018-05-17
CVE-2018-10473 [HIGH] CWE-787 CVE-2018-10473: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D CLOD Base Mesh Continuation structures. The i
nvd
CVE-2018-10491P3HIGHCVSS 8.8v9.0.0.299352018-05-17
CVE-2018-10491 [HIGH] CWE-787 CVE-2018-10491: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Bone Weight Modifier structures. The issue re
nvd
CVE-2018-10483P3HIGHCVSS 8.8v9.0.0.299352018-05-17
CVE-2018-10483 [HIGH] CWE-787 CVE-2018-10483: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Clod Progressive Mesh objects. The issue resu
nvd
CVE-2018-10477P3HIGHCVSS 8.8v9.0.0.299352018-05-17
CVE-2018-10477 [HIGH] CWE-787 CVE-2018-10477: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Chain Index objects. The issue results from t
nvd
CVE-2018-10474P3HIGHCVSS 8.8v9.0.0.299352018-05-17
CVE-2018-10474 [HIGH] CWE-787 CVE-2018-10474: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Shading objects. The issue results from the l
nvd
CVE-2018-10489P3HIGHCVSS 8.8v9.0.0.299352018-05-17
CVE-2018-10489 [HIGH] CWE-787 CVE-2018-10489: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Clod Progressive Mesh Declaration structures.
nvd
CVE-2023-28744P3HIGHCVSS 8.8v12.1.1.152892023-07-19
CVE-2023-28744 [HIGH] CWE-416 CVE-2023-28744: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, versi
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.1.1.15289. A specially crafted PDF document can trigger the reuse of previously freed memory by manipulating form fields of a specific type. This can lead to memory corruption and arbitrary code execution. An attacker needs to trick the user into
nvd
CVE-2023-27379P3HIGHCVSS 8.8v12.1.2.153322023-07-19
CVE-2023-27379 [HIGH] CWE-416 CVE-2023-27379: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, versi
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 12.1.2.15332. By prematurely deleting objects associated with pages, a specially crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the m
nvd
CVE-2023-33876P3HIGHCVSS 8.8v12.1.2.153322023-07-19
CVE-2023-33876 [HIGH] CWE-416 CVE-2023-33876: A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15332 handles destroying annota
A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15332 handles destroying annotations. Specially crafted Javascript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the mal
nvd
CVE-2023-33866P3HIGHCVSS 8.8v12.1.2.153322023-07-19
CVE-2023-33866 [HIGH] CWE-416 CVE-2023-33866: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, versi
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 12.1.2.15332. By prematurely deleting objects associated with pages, a specially crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the m
nvd
CVE-2024-29072P3HIGHCVSS 8.2v2024.2.0.251382024-05-28
CVE-2024-29072 [HIGH] CWE-295 CVE-2024-29072: A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability oc
A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which can result in unexpected elevation of privilege.
nvd
CVE-2022-37332P3HIGHCVSS 7.8v12.0.1.124302022-11-21
CVE-2022-37332 [HIGH] CWE-416 CVE-2022-37332: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, versi
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A specially-crafted PDF document can trigger the reuse of previously freed memory via misusing media player API, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger
nvd
CVE-2023-32664P3HIGHCVSS 7.8v12.1.2.153322023-07-19
CVE-2023-32664 [HIGH] CWE-843 CVE-2023-32664: A type confusion vulnerability exists in the Javascript checkThisBox method as implemented in Foxit
A type confusion vulnerability exists in the Javascript checkThisBox method as implemented in Foxit Reader 12.1.2.15332. Specially crafted Javascript code inside a malicious PDF document can cause memory corruption and lead to remote code execution. User would need to open a malicious file to trigger the vulnerability.
nvd
CVE-2022-32774P3HIGHCVSS 7.8v12.0.1.124302022-11-21
CVE-2022-32774 [HIGH] CWE-416 CVE-2022-32774: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, versi
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely deleting objects associated with pages, a specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the m
nvd
CVE-2022-40129P3HIGHCVSS 7.8v12.0.1.124302022-11-21
CVE-2022-40129 [HIGH] CWE-416 CVE-2022-40129: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, versi
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A specially-crafted PDF document can trigger the reuse of previously freed memory via misusing Optional Content Group API, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file t
nvd
CVE-2022-38097P3HIGHCVSS 7.8v12.0.1.124302022-11-21
CVE-2022-38097 [HIGH] CWE-416 CVE-2022-38097: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, versi
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely destroying annotation objects, a specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious
nvd
CVE-2018-9971P3MEDIUMCVSS 6.5v9.0.1.1042018-05-17
CVE-2018-9971 [MEDIUM] CWE-125 CVE-2018-9971: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.104. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within ConvertToPDF_x86.dll. The issue results from the lack of
nvd