cbcvebase.

Foxit Pdf Reader vulnerabilities

342 known vulnerabilities affecting foxit/pdf_reader.

Total CVEs
342
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH262MEDIUM47LOW30

Vulnerabilities

Page 12 of 18
CVE-2022-32774P3HIGHCVSS 7.8v12.0.1.124302022-11-21
CVE-2022-32774 [HIGH] CWE-416 CVE-2022-32774: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, versi A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely deleting objects associated with pages, a specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the m
nvd
CVE-2022-40129P3HIGHCVSS 7.8v12.0.1.124302022-11-21
CVE-2022-40129 [HIGH] CWE-416 CVE-2022-40129: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, versi A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A specially-crafted PDF document can trigger the reuse of previously freed memory via misusing Optional Content Group API, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file t
nvd
CVE-2022-38097P3HIGHCVSS 7.8v12.0.1.124302022-11-21
CVE-2022-38097 [HIGH] CWE-416 CVE-2022-38097: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, versi A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely destroying annotation objects, a specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious
nvd
CVE-2026-3780P3HIGHCVSS 7.8≤ 2025.3.0.357372026-04-01
CVE-2026-3780 [HIGH] CWE-426 CVE-2026-3780: The application's installer runs with elevated privileges but resolves system executables and DLLs u The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legitimate system files, resulting in local privilege escalat
nvd
CVE-2026-3777P3HIGHCVSS 7.8≤ 2025.3.0.35737≤ 2025.3.0.695702026-04-01
CVE-2026-3777 [HIGH] CWE-416 CVE-2026-3777: The application does not properly validate the lifetime and validity of internal view cache pointers The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and page state. When a script modifies the zoom property and then triggers a page change, the original view object may be destroyed while stale pointers are still kept and later dereferenced, which under crafted
nvd
CVE-2021-41782P3HIGHCVSS 7.8≥ 11.0, < 11.12022-08-29
CVE-2021-41782 [HIGH] CWE-416 CVE-2021-41782: Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attacke Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
nvd
CVE-2021-41781P3HIGHCVSS 7.8≥ 11.0, < 11.12022-08-29
CVE-2021-41781 [HIGH] CWE-416 CVE-2021-41781: Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attacke Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
nvd
CVE-2021-41785P3HIGHCVSS 7.8≥ 11.0, < 11.12022-08-29
CVE-2021-41785 [HIGH] CWE-416 CVE-2021-41785: Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attacke Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
nvd
CVE-2021-41783P3HIGHCVSS 7.8≥ 11.0, < 11.12022-08-29
CVE-2021-41783 [HIGH] CWE-416 CVE-2021-41783: Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attacke Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
nvd
CVE-2026-57239P3HIGHCVSS 7.8≤ 2026.1.1.364852026-07-08
CVE-2026-57239 [HIGH] CWE-427 CVE-2026-57239: The user-controllable executable files will be directly executed by high-privilege processes, allowi The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM.
nvd
CVE-2024-32488P3HIGHCVSS 7.8fixed in 2023.3.0.230282024-04-15
CVE-2024-32488 [HIGH] CWE-280 CVE-2024-32488: In Foxit PDF Reader and Editor before 2024.1, Local Privilege Escalation could occur during update c In Foxit PDF Reader and Editor before 2024.1, Local Privilege Escalation could occur during update checks because weak permissions on the update-service folder allow attackers to place crafted DLL files there.
nvd
CVE-2026-57250P3HIGHCVSS 7.8≤ 2026.1.1.36485≤ 2026.1.1.702762026-07-08
CVE-2026-57250 [HIGH] CWE-416 CVE-2026-57250: When the application opens a PDF and JavaScript resets the form fields, the script re-enters the int When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlying native object is damaged, but the application does not perform validation. The function call on the damaged object leads to the application crashing.
nvd
CVE-2024-12753P3HIGHCVSS 7.3≤ 2024.3.0.26795v2024.2.3.251842024-12-30
CVE-2024-12753 [HIGH] CWE-59 CVE-2024-12753: Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability. This vulnerability allows Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within th
nvd
CVE-2021-41784P3HIGHCVSS 7.8≥ 11.0, < 11.12022-08-29
CVE-2021-41784 [HIGH] CWE-416 CVE-2021-41784: Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attacke Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
nvd
CVE-2021-41780P3HIGHCVSS 7.8≥ 11.0, < 11.12022-08-29
CVE-2021-41780 [HIGH] CWE-416 CVE-2021-41780: Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attacke Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
nvd
CVE-2026-57251P3HIGHCVSS 7.8≤ 2026.1.1.364852026-07-08
CVE-2026-57251 [HIGH] CWE-129 CVE-2026-57251: The application opens a PDF, but the cloud-like appearance of the construction process lacks proper The application opens a PDF, but the cloud-like appearance of the construction process lacks proper setting of an upper limit and consistency checks. Out-of-bounds access to the underlying array is exposed, ultimately leading to a crash of the application.
nvd
CVE-2022-24368P3MEDIUMCVSS 6.5≤ 11.1.0.52543v11.1.0.525432022-02-18
CVE-2022-24368 [MEDIUM] CWE-416 CVE-2022-24368: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results fro
nvd
CVE-2026-5943P3HIGHCVSS 7.8fixed in 2026.1.12026-04-27
CVE-2026-5943 [HIGH] CWE-416 CVE-2026-5943: Document structural anomalies caused inconsistencies between page element relationships and internal Document structural anomalies caused inconsistencies between page element relationships and internal index states. When scripts triggered document modifications, object reference validity was not properly maintained, leading to a crash when accessing an invalid pointer during page information queries.
nvd
CVE-2026-13126P3HIGHCVSS 7.8≤ 2026.1.1.364852026-07-08
CVE-2026-13126 [HIGH] CWE-416 CVE-2026-13126: The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application att The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invalid pop-up annotations, resulting in the program crashing.
nvd
CVE-2026-57249P3HIGHCVSS 7.8≤ 2026.1.1.364852026-07-08
CVE-2026-57249 [HIGH] CWE-416 CVE-2026-57249: After the application opened the PDF file, the script first reset the annotation status, then trigge After the application opened the PDF file, the script first reset the annotation status, then triggered the reset form event by additional action. During the re-entry process, the application access invalid objects and crashed.
nvd
Foxit Pdf Reader vulnerabilities | cvebase