Foxit Pdf Reader vulnerabilities
342 known vulnerabilities affecting foxit/pdf_reader.
Total CVEs
342
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH262MEDIUM47LOW30
Vulnerabilities
Page 3 of 18
CVE-2021-34839P3HIGHCVSS 7.8≤ 11.0.0.49893v11.0.0.498932021-08-04
CVE-2021-34839 [HIGH] CWE-416 CVE-2021-34839: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from t
nvd
CVE-2021-34852P3HIGHCVSS 7.8≤ 11.0.0.49893v11.0.0.498932021-08-04
CVE-2021-34852 [HIGH] CWE-416 CVE-2021-34852: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from t
nvd
CVE-2021-34840P3HIGHCVSS 7.8≤ 11.0.0.49893v11.0.0.498932021-08-04
CVE-2021-34840 [HIGH] CWE-416 CVE-2021-34840: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from t
nvd
CVE-2021-34846P3HIGHCVSS 7.8≤ 11.0.0.49893v11.0.0.498932021-08-04
CVE-2021-34846 [HIGH] CWE-416 CVE-2021-34846: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from t
nvd
CVE-2021-34853P3HIGHCVSS 7.8≤ 11.0.0.49893v11.0.0.498932021-08-04
CVE-2021-34853 [HIGH] CWE-416 CVE-2021-34853: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from t
nvd
CVE-2021-34832P3HIGHCVSS 7.8≤ 11.0.0.49893v11.0.0.498932021-08-04
CVE-2021-34832 [HIGH] CWE-416 CVE-2021-34832: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the delay property. The issue results from t
nvd
CVE-2021-34837P3HIGHCVSS 7.8≤ 11.0.0.49893v11.0.0.498932021-08-04
CVE-2021-34837 [HIGH] CWE-416 CVE-2021-34837: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from t
nvd
CVE-2021-34841P3HIGHCVSS 7.8≤ 11.0.0.49893v11.0.0.498932021-08-04
CVE-2021-34841 [HIGH] CWE-416 CVE-2021-34841: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from t
nvd
CVE-2021-34844P3HIGHCVSS 7.8≤ 11.0.0.49893v11.0.0.498932021-08-04
CVE-2021-34844 [HIGH] CWE-416 CVE-2021-34844: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from t
nvd
CVE-2021-34851P3HIGHCVSS 7.8≤ 11.0.0.49893v11.0.0.498932021-08-04
CVE-2021-34851 [HIGH] CWE-416 CVE-2021-34851: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from t
nvd
CVE-2021-34845P3HIGHCVSS 7.8≤ 11.0.0.49893v11.0.0.498932021-08-04
CVE-2021-34845 [HIGH] CWE-416 CVE-2021-34845: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from t
nvd
CVE-2021-34836P3HIGHCVSS 7.8≤ 11.0.0.49893v11.0.0.498932021-08-04
CVE-2021-34836 [HIGH] CWE-416 CVE-2021-34836: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from t
nvd
CVE-2021-34838P3HIGHCVSS 7.8≤ 11.0.0.49893v11.0.0.498932021-08-04
CVE-2021-34838 [HIGH] CWE-416 CVE-2021-34838: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from t
nvd
CVE-2021-34848P3HIGHCVSS 7.8≤ 11.0.0.49893v11.0.0.498932021-08-04
CVE-2021-34848 [HIGH] CWE-416 CVE-2021-34848: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from t
nvd
CVE-2023-28744P3HIGHCVSS 8.8v12.1.1.152892023-07-19
CVE-2023-28744 [HIGH] CWE-416 CVE-2023-28744: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, versi
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.1.1.15289. A specially crafted PDF document can trigger the reuse of previously freed memory by manipulating form fields of a specific type. This can lead to memory corruption and arbitrary code execution. An attacker needs to trick the user into
nvd
CVE-2021-34835P3HIGHCVSS 7.8≤ 11.0.0.49893v11.0.0.498932021-08-04
CVE-2021-34835 [HIGH] CWE-416 CVE-2021-34835: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from t
nvd
CVE-2021-34834P3HIGHCVSS 7.8≤ 11.0.0.49893v11.0.0.498932021-08-04
CVE-2021-34834 [HIGH] CWE-416 CVE-2021-34834: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from t
nvd
CVE-2023-27379P3HIGHCVSS 8.8v12.1.2.153322023-07-19
CVE-2023-27379 [HIGH] CWE-416 CVE-2023-27379: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, versi
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 12.1.2.15332. By prematurely deleting objects associated with pages, a specially crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the m
nvd
CVE-2021-34831P3HIGHCVSS 7.8≤ 11.0.0.498932021-08-04
CVE-2021-34831 [HIGH] CWE-416 CVE-2021-34831: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.4.37651. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Document objects. The issue results from the lac
nvd
CVE-2023-33876P3HIGHCVSS 8.8v12.1.2.153322023-07-19
CVE-2023-33876 [HIGH] CWE-416 CVE-2023-33876: A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15332 handles destroying annota
A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15332 handles destroying annotations. Specially crafted Javascript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the mal
nvd