Foxit Pdf Reader vulnerabilities
342 known vulnerabilities affecting foxit/pdf_reader.
Total CVEs
342
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH262MEDIUM47LOW30
Vulnerabilities
Page 1 of 18
CVE-2021-34833P2HIGHCVSS 7.8≤ 11.0.0.49893v11.0.0.498932021-08-04
CVE-2021-34833 [HIGH] CWE-416 CVE-2021-34833: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from t
nvd
CVE-2021-34847P2HIGHCVSS 7.8≤ 11.0.0.49893v11.0.0.498932021-08-04
CVE-2021-34847 [HIGH] CWE-416 CVE-2021-34847: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from t
nvd
CVE-2023-27363P2HIGHCVSS 7.8fixed in 12.1.1.15289v12.1.0.152502024-05-03
CVE-2023-27363 [HIGH] CWE-749 CVE-2023-27363: Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability. This vu
Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specifi
nvd
CVE-2024-25575P2HIGHCVSS 8.8v2024.1.0.239972024-04-30
CVE-2024-25575 [HIGH] CWE-843 CVE-2024-25575: A type confusion vulnerability vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a
A type confusion vulnerability vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Lock object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious
nvd
CVE-2021-34850P3HIGHCVSS 7.8≤ 11.0.0.49893v11.0.0.498932021-08-04
CVE-2021-34850 [HIGH] CWE-416 CVE-2021-34850: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from t
nvd
CVE-2024-25648P3HIGHCVSS 8.8v2024.1.0.23997v2024.1.0.636822024-04-30
CVE-2024-25648 [HIGH] CWE-416 CVE-2024-25648: A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a ComboBox widg
A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a ComboBox widget. A specially crafted JavaScript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the mali
nvd
CVE-2024-25938P3HIGHCVSS 8.8v2024.1.0.239972024-04-30
CVE-2024-25938 [HIGH] CWE-416 CVE-2024-25938: A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Barcode widge
A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Barcode widget. A specially crafted JavaScript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malic
nvd
CVE-2022-24954P3CRITICALCVSS 9.8≤ 11.1.0.525432022-02-11
CVE-2022-24954 [CRITICAL] CWE-787 CVE-2022-24954: Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow
Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpan="-2"' and 'draw colSpan="1"' substrings.
nvd
CVE-2022-24363P3HIGHCVSS 8.8≤ 11.1.0.52543v11.1.0.525432022-02-18
CVE-2022-24363 [HIGH] CWE-416 CVE-2022-24363: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from t
nvd
CVE-2022-24364P3HIGHCVSS 8.8≤ 11.1.0.52543v11.1.0.525432022-02-18
CVE-2022-24364 [HIGH] CWE-416 CVE-2022-24364: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack
nvd
CVE-2022-24357P3HIGHCVSS 8.8≤ 11.1.0.52543v11.1.0.525432022-02-18
CVE-2022-24357 [HIGH] CWE-416 CVE-2022-24357: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from t
nvd
CVE-2022-24360P3HIGHCVSS 8.8≤ 11.1.0.52543v11.1.0.525432022-02-18
CVE-2022-24360 [HIGH] CWE-416 CVE-2022-24360: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack
nvd
CVE-2022-24359P3HIGHCVSS 8.8≤ 11.1.0.52543v11.1.0.525432022-02-18
CVE-2022-24359 [HIGH] CWE-416 CVE-2022-24359: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack
nvd
CVE-2022-24365P3HIGHCVSS 8.8≤ 11.1.0.52543v11.1.0.525432022-02-18
CVE-2022-24365 [HIGH] CWE-416 CVE-2022-24365: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of AcroForms. The issue results from the lack o
nvd
CVE-2022-24362P3HIGHCVSS 8.8≤ 11.1.0.52543v11.1.0.525432022-02-18
CVE-2022-24362 [HIGH] CWE-416 CVE-2022-24362: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of AcroForms. The issue results from the lack of
nvd
CVE-2022-24367P3HIGHCVSS 8.8≤ 11.1.0.52543v11.1.0.525432022-02-18
CVE-2022-24367 [HIGH] CWE-416 CVE-2022-24367: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of AcroForms. The issue results from the lack o
nvd
CVE-2022-24366P3HIGHCVSS 8.8≤ 11.1.0.52543v11.1.0.525432022-02-18
CVE-2022-24366 [HIGH] CWE-416 CVE-2022-24366: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of AcroForms. The issue results from the lack o
nvd
CVE-2024-9254P3HIGHCVSS 8.8≤ 2024.2.3.25184≤ 2024.2.2.64388+1 more2024-11-22
CVE-2024-9254 [HIGH] CWE-416 CVE-2024-9254: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability a
Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists w
nvd
CVE-2024-7725P3HIGHCVSS 8.8fixed in 2024.2.3.25184v2024.1.0.239972024-08-21
CVE-2024-7725 [HIGH] CWE-416 CVE-2024-7725: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability all
Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists wit
nvd
CVE-2024-7724P3HIGHCVSS 8.8fixed in 2024.2.3.25184v2024.1.0.239972024-08-21
CVE-2024-7724 [HIGH] CWE-416 CVE-2024-7724: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability all
Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists wit
nvd
1 / 18Next →