Foxit Pdf Editor vulnerabilities
266 known vulnerabilities affecting foxit/pdf_editor.
Total CVEs
266
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH197MEDIUM36LOW30
Vulnerabilities
Page 14 of 14
CVE-2022-24370MEDIUMCVSS 6.5fixed in 11.1.0.09252022-02-18
CVE-2022-24370 [MEDIUM] CWE-125 CVE-2022-24370: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader Foxit reader 11.0.1.0719 macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of XFA forms. The i
nvd
CVE-2022-24954CRITICALCVSS 9.8≤ 10.1.6.37749≥ 11.0.1.0719, ≤ 11.2.0.534152022-02-11
CVE-2022-24954 [CRITICAL] CWE-787 CVE-2022-24954: Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow
Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpan="-2"' and 'draw colSpan="1"' substrings.
nvd
CVE-2022-24955CRITICALCVSS 9.8≤ 10.1.6.37749≥ 11.0.1.0719, ≤ 11.2.0.534152022-02-11
CVE-2022-24955 [CRITICAL] CWE-427 CVE-2022-24955: Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path E
Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.
nvd
CVE-2021-45978HIGHCVSS 7.8fixed in 11.12022-01-04
CVE-2021-45978 [HIGH] CWE-78 CVE-2021-45978: Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary cod
Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via xfa.host.gotoURL in the XFA API.
nvd
CVE-2021-45979HIGHCVSS 7.8fixed in 11.12022-01-04
CVE-2021-45979 [HIGH] CWE-78 CVE-2021-45979: Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary cod
Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via app.launchURL in the JavaScript API.
nvd
CVE-2021-45980HIGHCVSS 7.8fixed in 11.12022-01-04
CVE-2021-45980 [HIGH] CVE-2021-45980: Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary cod
Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via getURL in the JavaScript API.
nvd
← Previous14 / 14