cbcvebase.

Foxit Pdf Reader vulnerabilities

342 known vulnerabilities affecting foxit/pdf_reader.

Total CVEs
342
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH262MEDIUM47LOW30

Vulnerabilities

Page 16 of 18
CVE-2026-57243P4MEDIUMCVSS 6.1≤ 2026.1.1.364852026-07-08
CVE-2026-57243 [MEDIUM] CWE-125 CVE-2026-57243: During the process of page opening and form formatting, a JavaScript reentrancy results in an incons During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document status. Subsequently, with outdated page information, the application attempts to access invalid addresses, causing the application to crash.
nvd
CVE-2026-57241P4MEDIUMCVSS 6.1≤ 2026.1.1.364852026-07-08
CVE-2026-57241 [MEDIUM] CWE-125 CVE-2026-57241: The application opens the PDF, and JavaScript performs operations on the page and the document, caus The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related objects within the application to lose synchronization; however, the renderer still trusts the outdated page count, and eventually the application crashes due to out-of-bounds access.
nvd
CVE-2026-5937P4MEDIUMCVSS 5.5fixed in 2026.1.12026-04-27
CVE-2026-5937 [MEDIUM] CWE-248 CVE-2026-5937: Insufficient parameter verification leads to the occurrence of format errors in files, which will tr Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "std::invalid_argument" exception, ultimately causing the program to terminate.
nvd
CVE-2022-25641P4MEDIUMCVSS 5.5≥ 11.0, < 11.2.22022-08-29
CVE-2022-25641 [MEDIUM] CVE-2022-25641: Foxit PDF Reader before 11.2.2 and PDF Editor before 11.2.2, and PhantomPDF before 10.1.8, mishandle Foxit PDF Reader before 11.2.2 and PDF Editor before 11.2.2, and PhantomPDF before 10.1.8, mishandle cross-reference information during compressed-object parsing within signed documents. This leads to delivery of incorrect signature information via an Incremental Saving Attack and a Shadow Attack.
nvd
CVE-2026-5942P4MEDIUMCVSS 5.5fixed in 2026.1.12026-04-27
CVE-2026-5942 [MEDIUM] CWE-416 CVE-2026-5942: Flaws in page lifecycle management allow document structure changes to desynchronize internal compon Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to access invalidated objects and crash the program.
nvd
CVE-2026-5940P4MEDIUMCVSS 5.5fixed in 2026.1.12026-04-27
CVE-2026-5940 [MEDIUM] CWE-416 CVE-2026-5940: Calling a function that triggers a UI refresh after removing comments via a script may access an inv Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes.
nvd
CVE-2026-3776P4MEDIUMCVSS 5.5≤ 2025.3.0.35737≤ 2025.3.0.695702026-04-01
CVE-2026-3776 [MEDIUM] CWE-476 CVE-2026-3776: The application does not validate the presence of required appearance (AP) data before accessing sta The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp annotation missing its AP entry, the code continues to dereference the associated object without a prior null or validity check, which allows a crafted document to trigger a null pointer dereference a
nvd
CVE-2022-25108P4MEDIUMCVSS 5.5fixed in 11.2.12022-03-10
CVE-2022-25108 [MEDIUM] CWE-476 CVE-2022-25108: Foxit PDF Reader and Editor before 11.2.1 and PhantomPDF before 10.1.7 allow a NULL pointer derefere Foxit PDF Reader and Editor before 11.2.1 and PhantomPDF before 10.1.7 allow a NULL pointer dereference during PDF parsing because the pointer is used without proper validation.
nvd
CVE-2026-5938P4MEDIUMCVSS 5.5fixed in 2026.1.12026-04-27
CVE-2026-5938 [MEDIUM] CWE-691 CVE-2026-5938: Improper control flow management allows a crafted document action chain to cause modal dialog reentr Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service.
nvd
CVE-2026-3778P4MEDIUMCVSS 5.5≤ 2025.3.0.35737≤ 2025.3.0.695702026-04-01
CVE-2026-3778 [MEDIUM] CWE-674 CVE-2026-3778: The application does not detect or guard against cyclic PDF object references while handling JavaScr The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pages and annotations are crafted that reference each other in a loop, passing the document to APIs (e.g., SOAP) that perform deep traversal can cause uncontrolled recursion, stack exhaustion, and application crashes.
nvd
CVE-2022-27359P4MEDIUMCVSS 5.5fixed in 12.0.12022-05-05
CVE-2022-27359 [MEDIUM] CWE-476 CVE-2022-27359: Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a this.maildoc NULL pointer derefe Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a this.maildoc NULL pointer dereference.
nvd
CVE-2020-35990P4MEDIUMCVSS 5.5≤ 10.1.0.375272023-08-11
CVE-2020-35990 [MEDIUM] CWE-120 CVE-2020-35990: Buffer Overflow vulnerability in cFilenameInit parameter in browseForDoc function in Foxit Software Buffer Overflow vulnerability in cFilenameInit parameter in browseForDoc function in Foxit Software Foxit PDF Reader version 10.1.0.37527, allows local attackers to cause a denial of service (DoS) via crafted .pdf file.
nvd
CVE-2023-51559P4LOWCVSS 3.3≤ 2023.2.0.21408≤ 2023.2.0.61611+1 more2024-05-03
CVE-2023-51559 [LOW] CWE-125 CVE-2023-51559: Foxit PDF Reader Doc Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allo Foxit PDF Reader Doc Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists wit
nvd
CVE-2024-30329P4LOWCVSS 3.3fixed in 2023.3.0.23028v2023.2.0.214082024-04-03
CVE-2024-30329 [LOW] CWE-416 CVE-2024-30329: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw
nvd
CVE-2023-38113P4LOWCVSS 3.3≤ 12.1.2.15332fixed in 12.1.0.1229+1 more2024-05-03
CVE-2023-38113 [LOW] CWE-416 CVE-2023-38113: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw
nvd
CVE-2023-42093P4LOWCVSS 3.3≤ 12.1.3.15356v12.1.3.153562024-05-03
CVE-2023-42093 [LOW] CWE-416 CVE-2023-42093: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw
nvd
CVE-2023-42098P4LOWCVSS 3.3≤ 12.1.3.15356v12.1.3.153562024-05-03
CVE-2023-42098 [LOW] CWE-416 CVE-2023-42098: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw
nvd
CVE-2022-34874P4LOWCVSS 3.3≤ 11.2.2.53575v11.2.2.535752022-07-18
CVE-2022-34874 [LOW] CWE-125 CVE-2022-34874: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.2.53575. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in
nvd
CVE-2022-34873P4LOWCVSS 3.3≤ 11.2.2.53575v11.2.1.535372022-07-18
CVE-2022-34873 [LOW] CWE-125 CVE-2022-34873: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. By performing act
nvd
CVE-2022-34875P4LOWCVSS 3.3≤ 11.2.2.53575v11.2.1.535372022-07-18
CVE-2022-34875 [LOW] CWE-125 CVE-2022-34875: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of ADBC objects. By performing actions i
nvd
Foxit Pdf Reader vulnerabilities | cvebase