cbcvebase.

Foxit Pdf Editor vulnerabilities

298 known vulnerabilities affecting foxit/pdf_editor.

Total CVEs
298
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH220MEDIUM45LOW30

Vulnerabilities

Page 13 of 15
CVE-2024-30363P4MEDIUMCVSS 5.5≤ 11.1.6.0109≥ 12.0.0.0601, ≤ 12.1.2.55366+7 more2024-04-02
CVE-2024-30363 [MEDIUM] CWE-125 CVE-2024-30363: Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vuln Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The
nvd
CVE-2021-34973P4MEDIUMCVSS 5.5≤ 10.1.5.37672v11.0.0.49893+1 more2024-05-07
CVE-2021-34973 [MEDIUM] CWE-416 CVE-2021-34973: Foxit PDF Reader PDF File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerab Foxit PDF Reader PDF File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The spe
nvd
CVE-2021-34970P4MEDIUMCVSS 5.5≤ 10.1.5.37672v11.0.0.49893+1 more2024-05-07
CVE-2021-34970 [MEDIUM] CWE-134 CVE-2021-34970: Foxit PDF Reader print Method Use of Externally-Controlled Format String Information Disclosure Vuln Foxit PDF Reader print Method Use of Externally-Controlled Format String Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a
nvd
CVE-2025-9323P4MEDIUMCVSS 5.5≤ 13.1.7.23637≥ 2023.1.0.15510, ≤ 2023.3.0.23028+2 more2025-09-02
CVE-2025-9323 [MEDIUM] CWE-125 CVE-2025-9323: Foxit PDF Reader JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vuln Foxit PDF Reader JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The s
nvd
CVE-2025-9325P4MEDIUMCVSS 5.5≤ 13.1.7.23637≥ 2023.1.0.15510, ≤ 2023.3.0.23028+6 more2025-09-02
CVE-2025-9325 [MEDIUM] CWE-125 CVE-2025-9325: Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vuln Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The s
nvd
CVE-2025-9327P4MEDIUMCVSS 5.5≤ 13.1.7.23637≥ 2023.1.0.15510, ≤ 2023.3.0.23028+2 more2025-09-02
CVE-2025-9327 [MEDIUM] CWE-125 CVE-2025-9327: Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vuln Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The s
nvd
CVE-2025-9324P4MEDIUMCVSS 5.5≤ 13.1.7.23637≥ 2023.1.0.15510, ≤ 2023.3.0.23028+6 more2025-09-02
CVE-2025-9324 [MEDIUM] CWE-125 CVE-2025-9324: Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vuln Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The s
nvd
CVE-2023-51561P4MEDIUMCVSS 5.5≤ 10.1.12.37872≥ 11.0.0, ≤ 11.2.7.53812+4 more2024-05-03
CVE-2023-51561 [MEDIUM] CWE-125 CVE-2023-51561: Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vuln Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The
nvd
CVE-2021-34949P4MEDIUMCVSS 5.5≤ 10.1.5.37672v11.0.0.49893+1 more2024-05-07
CVE-2021-34949 [MEDIUM] CWE-125 CVE-2021-34949: Foxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabil Foxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The speci
nvd
CVE-2025-59803P4MEDIUMCVSS 5.3≤ 13.2.0.63256≥ 2023.1.0.55583, ≤ 2023.3.0.63083+10 more2025-12-11
CVE-2025-59803 [MEDIUM] CWE-347 CVE-2025-59803: Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker can e Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker can embed triggers (e.g., JavaScript) in a PDF document that execute during the signing process. When a signer reviews the document, the content appears normal. However, once the signature is applied, the triggers modify content on other pages or optional
nvd
CVE-2021-40326P4MEDIUMCVSS 5.5≥ 11.0, < 11.12022-08-29
CVE-2021-40326 [MEDIUM] CWE-347 CVE-2021-40326: Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hid Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An attacker can write to an arbitrary file, and display controlled contents, during signature verification.
nvd
CVE-2024-7722P4MEDIUMCVSS 4.3fixed in 11.2.11.54113≥ 12.0.0.12394, < 12.1.8.15703+2 more2024-08-21
CVE-2024-7722 [MEDIUM] CWE-416 CVE-2024-7722: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability. This vulnerability Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific fla
nvd
CVE-2026-57258P4MEDIUMCVSS 6.1≤ 13.2.4.24048≥ 14.0.0.33046, ≤ 14.0.4.33508+10 more2026-07-08
CVE-2026-57258 [MEDIUM] CWE-125 CVE-2026-57258: The PRC file header parsing logic trusts the constructed file structure description information, ass The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underlying array contains elements and reads them, leading to out-of-bounds reads and application crashes.
nvd
CVE-2026-57255P4MEDIUMCVSS 6.1≤ 13.2.4.24048≥ 14.0.0.33046, ≤ 14.0.4.33508+4 more2026-07-08
CVE-2026-57255 [MEDIUM] CWE-125 CVE-2026-57255: The application opens a PDF containing an abnormal color space whose attributes reference a valid bu The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malformed function. The function's output is not validated; when subsequently read, it produces an illegal pointer that accesses an out-of-bounds region, crashing the application.
nvd
CVE-2026-57257P4MEDIUMCVSS 6.1≤ 13.2.4.24048≥ 14.0.0.33046, ≤ 14.0.4.33508+10 more2026-07-08
CVE-2026-57257 [MEDIUM] CWE-125 CVE-2026-57257: During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, whi During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-of-bounds read of the entity array. As a result, the application crashes.
nvd
CVE-2026-5939P4MEDIUMCVSS 5.5≥ 14.0.0, < 14.0.4≥ 2023.0.0, < 2026.1.12026-04-27
CVE-2026-5939 [MEDIUM] CWE-416 CVE-2026-5939: A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution.
nvd
CVE-2026-57253P4MEDIUMCVSS 6.1≤ 13.2.4.24048≥ 14.0.0.33046, ≤ 14.0.4.33508+4 more2026-07-08
CVE-2026-57253 [MEDIUM] CWE-125 CVE-2026-57253: An abnormal image object causes the renderer to enter the wrong processing branch. When converting t An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an invalid image buffer pointer is used, resulting in the application crashing.
nvd
CVE-2026-57243P4MEDIUMCVSS 6.1≤ 13.2.4.24048≥ 14.0.0.33046, ≤ 14.0.4.33508+4 more2026-07-08
CVE-2026-57243 [MEDIUM] CWE-125 CVE-2026-57243: During the process of page opening and form formatting, a JavaScript reentrancy results in an incons During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document status. Subsequently, with outdated page information, the application attempts to access invalid addresses, causing the application to crash.
nvd
CVE-2026-57241P4MEDIUMCVSS 6.1≤ 13.2.4.24048≥ 14.0.0.33046, ≤ 14.0.4.33508+4 more2026-07-08
CVE-2026-57241 [MEDIUM] CWE-125 CVE-2026-57241: The application opens the PDF, and JavaScript performs operations on the page and the document, caus The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related objects within the application to lose synchronization; however, the renderer still trusts the outdated page count, and eventually the application crashes due to out-of-bounds access.
nvd
CVE-2026-5937P4MEDIUMCVSS 5.5fixed in 13.2.4≥ 14.0.0, < 14.0.4+1 more2026-04-27
CVE-2026-5937 [MEDIUM] CWE-248 CVE-2026-5937: Insufficient parameter verification leads to the occurrence of format errors in files, which will tr Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "std::invalid_argument" exception, ultimately causing the program to terminate.
nvd
Foxit Pdf Editor vulnerabilities | cvebase