Foxit Reader vulnerabilities
155 known vulnerabilities affecting foxit/reader.
Total CVEs
155
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH129MEDIUM14LOW12
Vulnerabilities
Page 4 of 8
CVE-2018-17673P3HIGHCVSS 8.8v9.2.0.92972019-01-24
CVE-2018-17673 [HIGH] CWE-416 CVE-2018-17673: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the subtype property of a Annotation object. The
nvd
CVE-2018-17672P3HIGHCVSS 8.8v9.2.0.92972019-01-24
CVE-2018-17672 [HIGH] CWE-416 CVE-2018-17672: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of array indices. The issue results from the lack of
nvd
CVE-2018-17677P3HIGHCVSS 8.8v9.2.0.92972019-01-24
CVE-2018-17677 [HIGH] CWE-416 CVE-2018-17677: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the mailDoc method of a app object. The issue res
nvd
CVE-2018-17674P3HIGHCVSS 8.8v9.2.0.92972019-01-24
CVE-2018-17674 [HIGH] CWE-416 CVE-2018-17674: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the name property of Annotation objects. The issu
nvd
CVE-2018-17676P3HIGHCVSS 8.8v9.2.0.92972019-01-24
CVE-2018-17676 [HIGH] CWE-416 CVE-2018-17676: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the removeField property of a app object. The iss
nvd
CVE-2018-17675P3HIGHCVSS 8.8v9.2.0.92972019-01-24
CVE-2018-17675 [HIGH] CWE-416 CVE-2018-17675: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the removeDataObject method of a document. The is
nvd
CVE-2018-17678P3HIGHCVSS 8.8v9.2.0.92972019-01-24
CVE-2018-17678 [HIGH] CWE-416 CVE-2018-17678: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the gotoNamedDest method of a app object. The iss
nvd
CVE-2018-17685P3HIGHCVSS 8.8v9.2.0.92972019-01-24
CVE-2018-17685 [HIGH] CWE-843 CVE-2018-17685: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of PDF files. The issue results from the lack of pro
nvd
CVE-2019-6729P3HIGHCVSS 8.8v9.3.0.108262019-03-21
CVE-2019-6729 [HIGH] CWE-125 CVE-2019-6729: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from the lack of proper validat
nvd
CVE-2020-17417P3HIGHCVSS 7.8v10.0.1.358112020-10-13
CVE-2020-17417 [HIGH] CWE-416 CVE-2020-17417: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.0.1.35811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the Annotation objects. The issue results from t
nvd
CVE-2018-17671P3HIGHCVSS 8.8v9.2.0.92972019-01-24
CVE-2018-17671 [HIGH] CWE-125 CVE-2018-17671: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the Lower method of a XFA object. The is
nvd
CVE-2020-8857P3HIGHCVSS 7.8v9.7.0.294552020-02-14
CVE-2020-8857 [HIGH] CWE-416 CVE-2020-8857: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of form Annotation objects within AcroForms. The issue
nvd
CVE-2018-17686P3MEDIUMCVSS 6.5v9.2.0.92972019-01-24
CVE-2018-17686 [MEDIUM] CWE-125 CVE-2018-17686: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of BMP images. The issue results from t
nvd
CVE-2020-17416P3HIGHCVSS 7.8v10.0.0.357982020-10-13
CVE-2020-17416 [HIGH] CWE-787 CVE-2020-17416: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.0.0.35798. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPEG2000 images. The issue results from the lack
nvd
CVE-2019-13315P3HIGHCVSS 7.8v9.5.0.207232019-10-04
CVE-2019-13315 [HIGH] CWE-416 CVE-2019-13315: This vulnerability allows remote atackers to execute arbitrary code on affected installations of Fox
This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the removeField method. The issue results from the lack of validat
nvd
CVE-2020-10906P3HIGHCVSS 7.8v9.7.1.295112020-04-22
CVE-2020-10906 [HIGH] CWE-416 CVE-2020-10906: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the resetForm method. The issue results from the lack of validati
nvd
CVE-2020-10907P3HIGHCVSS 7.8v9.7.1.295112020-04-22
CVE-2020-10907 [HIGH] CWE-416 CVE-2020-10907: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of widgets in XFA forms. The issue results from the
nvd
CVE-2020-10900P3HIGHCVSS 7.8v9.7.1.295112020-04-22
CVE-2020-10900 [HIGH] CWE-416 CVE-2020-10900: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of AcroForms. The issue results from the lack of v
nvd
CVE-2020-10899P3HIGHCVSS 7.8v9.7.1.295112020-04-22
CVE-2020-10899 [HIGH] CWE-416 CVE-2020-10899: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XFA templates. The issue results from the lack
nvd
CVE-2019-13319P3HIGHCVSS 7.8v9.5.0.207232019-10-04
CVE-2019-13319 [HIGH] CWE-416 CVE-2019-13319: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XFA forms. The issue results from the lack of v
nvd