Foxit Pdf Editor vulnerabilities
298 known vulnerabilities affecting foxit/pdf_editor.
Total CVEs
298
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH220MEDIUM45LOW30
Vulnerabilities
Page 14 of 15
CVE-2022-25641P4MEDIUMCVSS 5.5≥ 11.0, < 11.2.22022-08-29
CVE-2022-25641 [MEDIUM] CVE-2022-25641: Foxit PDF Reader before 11.2.2 and PDF Editor before 11.2.2, and PhantomPDF before 10.1.8, mishandle
Foxit PDF Reader before 11.2.2 and PDF Editor before 11.2.2, and PhantomPDF before 10.1.8, mishandle cross-reference information during compressed-object parsing within signed documents. This leads to delivery of incorrect signature information via an Incremental Saving Attack and a Shadow Attack.
nvd
CVE-2026-5942P4MEDIUMCVSS 5.5fixed in 13.2.4≥ 14.0.0, < 14.0.4+1 more2026-04-27
CVE-2026-5942 [MEDIUM] CWE-416 CVE-2026-5942: Flaws in page lifecycle management allow document structure changes to desynchronize internal compon
Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to access invalidated objects and crash the program.
nvd
CVE-2026-5940P4MEDIUMCVSS 5.5fixed in 13.2.4≥ 14.0.0, < 14.0.4+1 more2026-04-27
CVE-2026-5940 [MEDIUM] CWE-416 CVE-2026-5940: Calling a function that triggers a UI refresh after removing comments via a script may access an inv
Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes.
nvd
CVE-2026-3776P4MEDIUMCVSS 5.5≤ 13.2.2.24014≥ 14.0.0.33046, ≤ 14.0.2.33402+8 more2026-04-01
CVE-2026-3776 [MEDIUM] CWE-476 CVE-2026-3776: The application does not validate the presence of required appearance (AP) data before accessing sta
The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp annotation missing its AP entry, the code continues to dereference the associated object without a prior null or validity check, which allows a crafted document to trigger a null pointer dereference a
nvd
CVE-2022-25108P4MEDIUMCVSS 5.5fixed in 10.1.7≥ 11.0, < 11.2.12022-03-10
CVE-2022-25108 [MEDIUM] CWE-476 CVE-2022-25108: Foxit PDF Reader and Editor before 11.2.1 and PhantomPDF before 10.1.7 allow a NULL pointer derefere
Foxit PDF Reader and Editor before 11.2.1 and PhantomPDF before 10.1.7 allow a NULL pointer dereference during PDF parsing because the pointer is used without proper validation.
nvd
CVE-2026-5938P4MEDIUMCVSS 5.5fixed in 13.2.4≥ 14.0.0, < 14.0.4+1 more2026-04-27
CVE-2026-5938 [MEDIUM] CWE-691 CVE-2026-5938: Improper control flow management allows a crafted document action chain to cause modal dialog reentr
Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service.
nvd
CVE-2026-3778P4MEDIUMCVSS 5.5≤ 13.2.2.24014≥ 14.0.0.33046, ≤ 14.0.2.33402+8 more2026-04-01
CVE-2026-3778 [MEDIUM] CWE-674 CVE-2026-3778: The application does not detect or guard against cyclic PDF object references while handling JavaScr
The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pages and annotations are crafted that reference each other in a loop, passing the document to APIs (e.g., SOAP) that perform deep traversal can cause uncontrolled recursion, stack exhaustion, and application crashes.
nvd
CVE-2022-27359P4MEDIUMCVSS 5.5fixed in 12.0.12022-05-05
CVE-2022-27359 [MEDIUM] CWE-476 CVE-2022-27359: Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a this.maildoc NULL pointer derefe
Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a this.maildoc NULL pointer dereference.
nvd
CVE-2023-51559P4LOWCVSS 3.3≤ 10.1.12.37872≥ 11.0.0, ≤ 11.2.7.53812+9 more2024-05-03
CVE-2023-51559 [LOW] CWE-125 CVE-2023-51559: Foxit PDF Reader Doc Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allo
Foxit PDF Reader Doc Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists wit
nvd
CVE-2024-30329P4LOWCVSS 3.3fixed in 10.1.12.37872≥ 11.0.0.49893, < 11.2.8.53842+3 more2024-04-03
CVE-2024-30329 [LOW] CWE-416 CVE-2024-30329: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability
Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw
nvd
CVE-2023-38113P4LOWCVSS 3.3≤ 10.1.12.37872≥ 11.0.0, ≤ 11.2.6.53790+3 more2024-05-03
CVE-2023-38113 [LOW] CWE-416 CVE-2023-38113: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability
Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw
nvd
CVE-2023-42093P4LOWCVSS 3.3≤ 10.1.12.37872≥ 11.0.0, ≤ 11.2.7.53812+2 more2024-05-03
CVE-2023-42093 [LOW] CWE-416 CVE-2023-42093: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability
Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw
nvd
CVE-2023-42098P4LOWCVSS 3.3≤ 10.1.12.37872≥ 11.0.0, ≤ 11.2.7.53812+2 more2024-05-03
CVE-2023-42098 [LOW] CWE-416 CVE-2023-42098: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability
Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw
nvd
CVE-2022-34874P4LOWCVSS 3.3≤ 10.1.8.37795≥ 11.0, ≤ 11.2.2.535752022-07-18
CVE-2022-34874 [LOW] CWE-125 CVE-2022-34874: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.2.53575. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in
nvd
CVE-2022-34873P4LOWCVSS 3.3≤ 10.1.8.37795≥ 11.0, ≤ 11.2.2.535752022-07-18
CVE-2022-34873 [LOW] CWE-125 CVE-2022-34873: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. By performing act
nvd
CVE-2022-34875P4LOWCVSS 3.3≤ 10.1.8.37795≥ 11.0, ≤ 11.2.2.535752022-07-18
CVE-2022-34875 [LOW] CWE-125 CVE-2022-34875: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of ADBC objects. By performing actions i
nvd
CVE-2022-37376P4LOWCVSS 3.3fixed in 10.1.9≥ 11.0.0, < 11.2.3+2 more2023-03-29
CVE-2022-37376 [LOW] CWE-125 CVE-2022-37376: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Editor 11.1.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of arrays. By performing actions in Java
nvd
CVE-2023-51554P4LOWCVSS 3.3≤ 10.1.12.37872≥ 11.0.0, ≤ 11.2.7.53812+9 more2024-05-03
CVE-2023-51554 [LOW] CWE-416 CVE-2023-51554: Foxit PDF Reader Signature Use-After-Free Information Disclosure Vulnerability. This vulnerability a
Foxit PDF Reader Signature Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw
nvd
CVE-2021-34951P4LOWCVSS 3.3≤ 10.1.5.37672≥ 11.0.0.0510, ≤ 11.0.0.49893+1 more2024-05-07
CVE-2021-34951 [LOW] CWE-457 CVE-2021-34951: Foxit PDF Reader Annotation Use of Uninitialized Variable Information Disclosure Vulnerability. This
Foxit PDF Reader Annotation Use of Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
T
nvd
CVE-2024-30364P4LOWCVSS 3.3≤ 10.1.12.37872≥ 11.0.0.49893, ≤ 11.2.8.53842+3 more2024-04-02
CVE-2024-30364 [LOW] CWE-125 CVE-2024-30364: Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vuln
Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The sp
nvd