Foxit Pdf Editor vulnerabilities
298 known vulnerabilities affecting foxit/pdf_editor.
Total CVEs
298
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH220MEDIUM45LOW30
Vulnerabilities
Page 9 of 15
CVE-2024-12751P3HIGHCVSS 7.8≥ 11.0.0, ≤ 11.2.11.54113≥ 12.0.0, ≤ 12.1.8.15703+3 more2024-12-30
CVE-2024-12751 [HIGH] CWE-125 CVE-2024-12751: Foxit PDF Reader AcroForm Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability
Foxit PDF Reader AcroForm Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exis
nvd
CVE-2021-34971P3HIGHCVSS 7.8≤ 10.1.5.37672v11.0.0.49893+1 more2024-05-07
CVE-2021-34971 [HIGH] CWE-122 CVE-2021-34971: Foxit PDF Reader JPG2000 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Foxit PDF Reader JPG2000 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Th
nvd
CVE-2026-3779P3HIGHCVSS 7.8≤ 13.2.2.24014≥ 14.0.0.33046, ≤ 14.0.2.33402+8 more2026-04-01
CVE-2026-3779 [HIGH] CWE-416 CVE-2026-3779: The application's list box calculate array logic keeps stale references to page or form objects afte
The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary code execution.
nvd
CVE-2025-9326P3HIGHCVSS 7.8≤ 13.1.7.23637≥ 2023.1.0.15510, ≤ 2023.3.0.23028+6 more2025-09-02
CVE-2025-9326 [HIGH] CWE-125 CVE-2025-9326: Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulne
Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific fla
nvd
CVE-2025-9329P3HIGHCVSS 7.8≤ 13.1.7.23637≥ 2023.1.0.15510, ≤ 2023.3.0.23028+6 more2025-09-02
CVE-2025-9329 [HIGH] CWE-125 CVE-2025-9329: Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulne
Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific fla
nvd
CVE-2025-9328P3HIGHCVSS 7.8≤ 13.1.7.23637≥ 2023.1.0.15510, ≤ 2023.3.0.23028+6 more2025-09-02
CVE-2025-9328 [HIGH] CWE-125 CVE-2025-9328: Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulne
Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific fla
nvd
CVE-2025-66498P3HIGHCVSS 7.8≤ 13.2.1.23955≥ 14.0.0.33046, ≤ 14.0.1.33197+3 more2025-12-19
CVE-2025-66498 [HIGH] CWE-125 CVE-2025-66498: A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to in
A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing U3D data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.
nvd
CVE-2025-66497P3HIGHCVSS 7.8≤ 13.2.1.23955≥ 14.0.0.33046, ≤ 14.0.1.33197+8 more2025-12-19
CVE-2025-66497 [HIGH] CWE-125 CVE-2025-66497: A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to in
A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.
nvd
CVE-2025-66496P3HIGHCVSS 7.8≤ 13.2.1.23955≥ 14.0.0.33046, ≤ 14.0.1.33197+3 more2025-12-19
CVE-2025-66496 [HIGH] CWE-125 CVE-2025-66496: A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to in
A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.
nvd
CVE-2025-55313P3HIGHCVSS 7.8≥ 2023.1.0.15510, ≤ 2023.3.0.23028≥ 2024.1.0.23997, ≤ 2024.4.1.27687+5 more2025-12-11
CVE-2025-55313 [HIGH] CWE-94 CVE-2025-55313: An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 20
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. They allow potential arbitrary code execution when processing crafted PDF files. The vulnerability stems from insufficient handling of memory allocation failures after assigning an extremely large value to a form field's charLimit property via Java
nvd
CVE-2026-3774P3HIGHCVSS 7.5≤ 13.2.2.24014≥ 14.0.0.33046, ≤ 14.0.2.33402+3 more2026-04-01
CVE-2026-3774 [HIGH] CWE-200 CVE-2026-3774: The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to upd
The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, annotations, or optional content groups (OCGs) immediately before or after redaction, encryption, or printing. These script‑driven updates are not fully covered by the existing redaction, encryption, and printing logic, which, under speci
nvd
CVE-2021-45979P3HIGHCVSS 7.8fixed in 11.12022-01-04
CVE-2021-45979 [HIGH] CWE-78 CVE-2021-45979: Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary cod
Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via app.launchURL in the JavaScript API.
nvd
CVE-2024-29072P3HIGHCVSS 8.2≤ 11.2.9.53938≥ 12.0.0, ≤ 12.1.6.15509+3 more2024-05-28
CVE-2024-29072 [HIGH] CWE-295 CVE-2024-29072: A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability oc
A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which can result in unexpected elevation of privilege.
nvd
CVE-2022-28670P3HIGHCVSS 7.8≤ 10.1.7.37777≥ 11.0, ≤ 11.2.1.535372022-07-18
CVE-2022-28670 [HIGH] CWE-125 CVE-2022-28670: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of AcroForms. Crafted data in an Acro
nvd
CVE-2022-37388P3HIGHCVSS 7.8fixed in 10.1.9≥ 11.0.0, < 11.2.3+1 more2023-03-29
CVE-2022-37388 [HIGH] CWE-125 CVE-2022-37388: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.2.53575. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can tri
nvd
CVE-2022-43641P3HIGHCVSS 7.8fixed in 10.1.10≥ 11.0.0, < 11.2.4+1 more2023-03-29
CVE-2022-43641 [HIGH] CWE-416 CVE-2022-43641: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 12.0.1.12430. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the
nvd
CVE-2021-34950P3HIGHCVSS 7.8≤ 10.1.5.37672v11.0.0.49893+1 more2024-05-07
CVE-2021-34950 [HIGH] CWE-125 CVE-2021-34950: Foxit PDF Reader Annotation Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerabili
Foxit PDF Reader Annotation Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw ex
nvd
CVE-2024-9244P3HIGHCVSS 7.8≤ 11.2.10.53951≥ 12.0, ≤ 12.1.7.15526+3 more2024-11-22
CVE-2024-9244 [HIGH] CWE-732 CVE-2024-9244: Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerabi
Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Th
nvd
CVE-2023-33240P3HIGHCVSS 7.8≤ 10.1.11.37866≥ 11.0.0, ≤ 11.2.5.53785+1 more2023-05-19
CVE-2023-33240 [HIGH] CWE-276 CVE-2023-33240: Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x
Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x versions, 11.2.5.53785 and all previous 11.x versions, and 10.1.11.37866 and earlier) on Windows allows Local Privilege Escalation when installed to a non-default directory because unprivileged users have access to an executable file of a system servic
nvd
CVE-2022-30557P3HIGHCVSS 7.5≤ 10.1.7.37777≥ 11.0, < 11.2.22022-05-11
CVE-2022-30557 [HIGH] CWE-843 CVE-2022-30557: Foxit PDF Reader and PDF Editor before 11.2.2 have a Type Confusion issue that causes a crash becaus
Foxit PDF Reader and PDF Editor before 11.2.2 have a Type Confusion issue that causes a crash because of Unsigned32 mishandling during JavaScript execution.
nvd