cbcvebase.

Foxit Pdf Editor vulnerabilities

299 known vulnerabilities affecting foxit/pdf_editor.

Total CVEs
299
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH220MEDIUM46LOW30

Vulnerabilities

Page 8 of 15
CVE-2025-66498P3HIGHCVSS 7.8≤ 13.2.1.23955≥ 14.0.0.33046, ≤ 14.0.1.33197+3 more2025-12-19
CVE-2025-66498 [HIGH] CWE-125 CVE-2025-66498: A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to in A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing U3D data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.
nvd
CVE-2025-66497P3HIGHCVSS 7.8≤ 13.2.1.23955≥ 14.0.0.33046, ≤ 14.0.1.33197+8 more2025-12-19
CVE-2025-66497 [HIGH] CWE-125 CVE-2025-66497: A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to in A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.
nvd
CVE-2025-66496P3HIGHCVSS 7.8≤ 13.2.1.23955≥ 14.0.0.33046, ≤ 14.0.1.33197+3 more2025-12-19
CVE-2025-66496 [HIGH] CWE-125 CVE-2025-66496: A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to in A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.
nvd
CVE-2025-55314P3HIGHCVSS 7.8≤ 13.1.7.23637≥ 2023.1.0.15510, ≤ 2023.3.0.23028+2 more2025-12-11
CVE-2025-55314 [HIGH] CWE-476 CVE-2025-55314: An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 20 An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume these states are valid, causing dereference of invalid or released memory. This can lea
nvd
CVE-2025-9330P3HIGHCVSS 7.8≤ 13.1.7.23637≥ 2023.1.0.15510, ≤ 2023.3.0.23028+2 more2025-09-02
CVE-2025-9330 [HIGH] CWE-427 CVE-2025-9330: Foxit PDF Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerab Foxit PDF Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. T
nvd
CVE-2025-55312P3HIGHCVSS 7.8≤ 13.1.7.63027≥ 2023.1.0.55583, ≤ 2023.3.0.63083+5 more2025-12-11
CVE-2025-55312 [HIGH] CWE-476 CVE-2025-55312: An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. When An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume these states are valid, causing dereference of invalid or released memory. This can lead to memor
nvd
CVE-2021-45980P3HIGHCVSS 7.8fixed in 11.12022-01-04
CVE-2021-45980 [HIGH] CVE-2021-45980: Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary cod Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via getURL in the JavaScript API.
nvd
CVE-2022-24908P3HIGHCVSS 7.8fixed in 10.1.7≥ 11.0.0, < 11.2.12023-03-28
CVE-2022-24908 [HIGH] CWE-125 CVE-2022-24908: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 images. Crafted data in a JP2 image can t
nvd
CVE-2022-24907P3HIGHCVSS 7.8fixed in 10.1.7≥ 11.0.0, < 11.2.12023-03-28
CVE-2022-24907 [HIGH] CWE-125 CVE-2022-24907: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 images. Crafted data in a JP2 image can t
nvd
CVE-2022-37377P3HIGHCVSS 7.8fixed in 10.1.9≥ 11.0.0, < 11.2.3+2 more2023-03-29
CVE-2022-37377 [HIGH] CWE-843 CVE-2022-37377: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Editor 11.1.1.53537;. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within JavaScript optimizations. The issue results from an imprope
nvd
CVE-2024-30323P3HIGHCVSS 7.8≤ 10.1.12.37872≥ 11.0.0.49893, ≤ 11.2.8.53842+3 more2024-04-03
CVE-2024-30323 [HIGH] CWE-125 CVE-2024-30323: Foxit PDF Reader template Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability Foxit PDF Reader template Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exis
nvd
CVE-2024-30348P3HIGHCVSS 7.8≤ 11.1.6.0109≥ 12.0.0.0601, ≤ 12.1.2.55366+7 more2024-04-02
CVE-2024-30348 [HIGH] CWE-787 CVE-2024-30348: Foxit PDF Reader U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vuln Foxit PDF Reader U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific
nvd
CVE-2024-30341P3HIGHCVSS 7.8≤ 10.1.12.37872≥ 11.0.0, < 11.2.8.53842+3 more2024-04-02
CVE-2024-30341 [HIGH] CWE-125 CVE-2024-30341: Foxit PDF Reader Doc Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerabili Foxit PDF Reader Doc Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw ex
nvd
CVE-2024-30359P3HIGHCVSS 7.8≤ 10.1.12.37872≥ 11.0.0.49893, ≤ 11.2.8.53842+3 more2024-04-02
CVE-2024-30359 [HIGH] CWE-125 CVE-2024-30359: Foxit PDF Reader AcroForm 3D Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerabil Foxit PDF Reader AcroForm 3D Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw e
nvd
CVE-2024-30349P3HIGHCVSS 7.8≤ 10.1.12.37872≥ 11.0.0.49893, ≤ 11.2.8.53842+3 more2024-04-02
CVE-2024-30349 [HIGH] CWE-787 CVE-2024-30349: Foxit PDF Reader U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vuln Foxit PDF Reader U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific
nvd
CVE-2024-9248P3HIGHCVSS 7.8≤ 11.2.10.53951≥ 12.0, ≤ 12.1.7.15526+3 more2024-11-22
CVE-2024-9248 [HIGH] CWE-787 CVE-2024-9248: Foxit PDF Reader PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vuln Foxit PDF Reader PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific fl
nvd
CVE-2023-38119P3HIGHCVSS 7.8≤ 10.1.12.37872≥ 11.0.0, ≤ 11.2.6.53790+1 more2024-05-03
CVE-2023-38119 [HIGH] CWE-125 CVE-2023-38119: Foxit PDF Reader AcroForm signature Out-Of-Bounds Read Remote Code Execution Vulnerability. This vul Foxit PDF Reader AcroForm signature Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific
nvd
CVE-2023-38118P3HIGHCVSS 7.8≤ 10.1.12.37872≥ 11.0.0, ≤ 11.2.6.53790+1 more2024-05-03
CVE-2023-38118 [HIGH] CWE-787 CVE-2023-38118: Foxit PDF Reader AcroForm Doc Object Out-Of-Bounds Write Remote Code Execution Vulnerability. This v Foxit PDF Reader AcroForm Doc Object Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specif
nvd
CVE-2023-42089P3HIGHCVSS 7.8≤ 10.1.12.37872≥ 11.0.0, ≤ 11.2.7.53812+2 more2024-05-03
CVE-2023-42089 [HIGH] CWE-416 CVE-2023-42089: Foxit PDF Reader templates Use-After-Free Information Disclosure Vulnerability. This vulnerability a Foxit PDF Reader templates Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific fla
nvd
CVE-2024-9251P3HIGHCVSS 7.8≤ 11.2.10.53951≥ 12.0, ≤ 12.1.7.15526+3 more2024-11-22
CVE-2024-9251 [HIGH] CWE-416 CVE-2024-9251: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw
nvd
Foxit Pdf Editor vulnerabilities | cvebase