cbcvebase.

Foxit Pdf Reader vulnerabilities

342 known vulnerabilities affecting foxit/pdf_reader.

Total CVEs
342
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH262MEDIUM47LOW30

Vulnerabilities

Page 11 of 18
CVE-2025-9328P3HIGHCVSS 7.8fixed in 2025.1.0.27937≤ 2025.1.0.66692+1 more2025-09-02
CVE-2025-9328 [HIGH] CWE-125 CVE-2025-9328: Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulne Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific fla
nvd
CVE-2025-66498P3HIGHCVSS 7.8≤ 2025.2.1.331972025-12-19
CVE-2025-66498 [HIGH] CWE-125 CVE-2025-66498: A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to in A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing U3D data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.
nvd
CVE-2025-66497P3HIGHCVSS 7.8≤ 2025.2.1.33197≤ 2025.2.1.690052025-12-19
CVE-2025-66497 [HIGH] CWE-125 CVE-2025-66497: A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to in A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.
nvd
CVE-2025-66496P3HIGHCVSS 7.8≤ 2025.2.1.331972025-12-19
CVE-2025-66496 [HIGH] CWE-125 CVE-2025-66496: A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to in A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.
nvd
CVE-2025-55313P3HIGHCVSS 7.8≤ 2025.1.0.27937≤ 2025.1.0.666922025-12-11
CVE-2025-55313 [HIGH] CWE-94 CVE-2025-55313: An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 20 An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. They allow potential arbitrary code execution when processing crafted PDF files. The vulnerability stems from insufficient handling of memory allocation failures after assigning an extremely large value to a form field's charLimit property via Java
nvd
CVE-2021-38563P3CRITICALCVSS 9.8≤ 11.0.0.05102021-08-11
CVE-2021-38563 [CRITICAL] CWE-129 CVE-2021-38563: An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It mishandle An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It mishandles situations in which an array size (derived from a /Size entry) is smaller than the maximum indirect object number, and thus there is an attempted incorrect array access (leading to a NULL pointer dereference, or out-of-bounds read or write).
nvd
CVE-2007-2186P4MEDIUMCVSS 5.0PoCv2.02007-04-24
CVE-2007-2186 [MEDIUM] CVE-2007-2186: Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a craf Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
nvd
CVE-2026-3774P3HIGHCVSS 7.5≤ 2025.3.0.357372026-04-01
CVE-2026-3774 [HIGH] CWE-200 CVE-2026-3774: The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to upd The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, annotations, or optional content groups (OCGs) immediately before or after redaction, encryption, or printing. These script‑driven updates are not fully covered by the existing redaction, encryption, and printing logic, which, under speci
nvd
CVE-2021-45979P3HIGHCVSS 7.8fixed in 11.12022-01-04
CVE-2021-45979 [HIGH] CWE-78 CVE-2021-45979: Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary cod Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via app.launchURL in the JavaScript API.
nvd
CVE-2024-29072P3HIGHCVSS 8.2≤ 2024.2.1.251532024-05-28
CVE-2024-29072 [HIGH] CWE-295 CVE-2024-29072: A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability oc A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which can result in unexpected elevation of privilege.
nvd
CVE-2022-37332P3HIGHCVSS 7.8v12.0.1.124302022-11-21
CVE-2022-37332 [HIGH] CWE-416 CVE-2022-37332: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, versi A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A specially-crafted PDF document can trigger the reuse of previously freed memory via misusing media player API, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger
nvd
CVE-2022-28670P3HIGHCVSS 7.8≤ 11.2.1.53537v11.2.1.535372022-07-18
CVE-2022-28670 [HIGH] CWE-125 CVE-2022-28670: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of AcroForms. Crafted data in an Acro
nvd
CVE-2022-37388P3HIGHCVSS 7.8fixed in 12.0.1v11.2.2.535752023-03-29
CVE-2022-37388 [HIGH] CWE-125 CVE-2022-37388: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.2.53575. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can tri
nvd
CVE-2022-43641P3HIGHCVSS 7.8fixed in 12.0.2v12.0.1.124302023-03-29
CVE-2022-43641 [HIGH] CWE-416 CVE-2022-43641: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 12.0.1.12430. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the
nvd
CVE-2021-34950P3HIGHCVSS 7.8≤ 11.0.1.49938v11.0.0.498932024-05-07
CVE-2021-34950 [HIGH] CWE-125 CVE-2021-34950: Foxit PDF Reader Annotation Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerabili Foxit PDF Reader Annotation Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw ex
nvd
CVE-2024-9244P3HIGHCVSS 7.8≤ 2024.2.3.25184v2024.1.0.239972024-11-22
CVE-2024-9244 [HIGH] CWE-732 CVE-2024-9244: Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerabi Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Th
nvd
CVE-2023-33240P3HIGHCVSS 7.8≤ 12.1.1.152892023-05-19
CVE-2023-33240 [HIGH] CWE-276 CVE-2023-33240: Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x versions, 11.2.5.53785 and all previous 11.x versions, and 10.1.11.37866 and earlier) on Windows allows Local Privilege Escalation when installed to a non-default directory because unprivileged users have access to an executable file of a system servic
nvd
CVE-2022-30557P3HIGHCVSS 7.5fixed in 11.2.22022-05-11
CVE-2022-30557 [HIGH] CWE-843 CVE-2022-30557: Foxit PDF Reader and PDF Editor before 11.2.2 have a Type Confusion issue that causes a crash becaus Foxit PDF Reader and PDF Editor before 11.2.2 have a Type Confusion issue that causes a crash because of Unsigned32 mishandling during JavaScript execution.
nvd
CVE-2024-25858P3HIGHCVSS 8.4fixed in 2024.42024-03-05
CVE-2024-25858 [HIGH] CWE-450 CVE-2024-25858: In Foxit PDF Reader before 2024.1 and PDF Editor before 2024.1, code execution via JavaScript could In Foxit PDF Reader before 2024.1 and PDF Editor before 2024.1, code execution via JavaScript could occur because of an unoptimized prompt message for users to review parameters of commands.
nvd
CVE-2023-32664P3HIGHCVSS 7.8v12.1.2.153322023-07-19
CVE-2023-32664 [HIGH] CWE-843 CVE-2023-32664: A type confusion vulnerability exists in the Javascript checkThisBox method as implemented in Foxit A type confusion vulnerability exists in the Javascript checkThisBox method as implemented in Foxit Reader 12.1.2.15332. Specially crafted Javascript code inside a malicious PDF document can cause memory corruption and lead to remote code execution. User would need to open a malicious file to trigger the vulnerability.
nvd
Foxit Pdf Reader vulnerabilities | cvebase