Foxitsoftware Foxit Reader vulnerabilities
372 known vulnerabilities affecting foxitsoftware/foxit_reader.
Total CVEs
372
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL22HIGH264MEDIUM75LOW11
Vulnerabilities
Page 1 of 19
CVE-2018-9958P2HIGHCVSS 8.8PoC≤ 9.0.1.10492018-05-17
CVE-2018-9958 [HIGH] CWE-416 CVE-2018-9958: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Text Annotations. When setting the point attribute,
nvd
CVE-2018-9948P2MEDIUMCVSS 6.5PoC≤ 9.0.1.10492018-05-17
CVE-2018-9948 [MEDIUM] CWE-824 CVE-2018-9948: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of typed arrays. The issue results from th
nvd
CVE-2020-14425P2HIGHCVSS 7.8PoC≥ 9.7.1, < 10.0.02020-11-02
CVE-2020-14425 [HIGH] CVE-2020-14425: Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API.
Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. An attacker can execute local files and bypass the security dialog.
nvd
CVE-2020-13557P2HIGHCVSS 8.8v10.1.0.37527vFoxit Reader Version: 10.1.0.375272020-12-22
CVE-2020-13557 [HIGH] CWE-416 CVE-2020-13557: A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader,
A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser
nvd
CVE-2020-13548P2HIGHCVSS 8.8v10.1.0.37527vFoxit Reader Version: 10.1.0.375272021-02-10
CVE-2020-13548 [HIGH] CWE-416 CVE-2020-13548: In Foxit Reader 10.1.0.37527, a specially crafted PDF document can trigger reuse of previously free
In Foxit Reader 10.1.0.37527, a specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
nvd
CVE-2010-1239P3CRITICALCVSS 9.3PoC≤ 3.2.0.0303v2.3+5 more2010-04-05
CVE-2010-1239 [CRITICAL] CVE-2010-1239: Foxit Reader before 3.2.1.0401 allows remote attackers to (1) execute arbitrary local programs via a
Foxit Reader before 3.2.1.0401 allows remote attackers to (1) execute arbitrary local programs via a certain "/Type /Action /S /Launch" sequence, and (2) execute arbitrary programs embedded in a PDF document via an unspecified "/Launch /Action" sequence, a related issue to CVE-2009-0836.
nvd
CVE-2018-3843P3HIGHCVSS 8.8v9.0.1.10492018-04-19
CVE-2018-3843 [HIGH] CWE-704 CVE-2018-3843: An exploitable type confusion vulnerability exists in the way Foxit PDF Reader version 9.0.1.1049 pa
An exploitable type confusion vulnerability exists in the way Foxit PDF Reader version 9.0.1.1049 parses files with associated file annotations. A specially crafted PDF document can lead to an object of invalid type to be dereferenced, which can potentially lead to sensitive memory disclosure, and possibly to arbitrary code execution. An attacker needs
nvd
CVE-2018-3924P3HIGHCVSS 7.8≤ 9.1.0.50962018-08-01
CVE-2018-3924 [HIGH] CWE-416 CVE-2018-3924: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxi
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulner
nvd
CVE-2015-2790P3MEDIUMCVSS 4.3PoC≤ 7.0.6.11262015-03-30
CVE-2015-2790 [MEDIUM] CWE-20 CVE-2015-2790: Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted (1) Ubyte Size in a DataSubBlock structure or (2) LZWMinimumCodeSize in a GIF image.
nvd
CVE-2018-14295P3HIGHCVSS 8.8≤ 9.1.0.50962018-07-31
CVE-2018-14295 [HIGH] CWE-190 CVE-2018-14295: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF Phantom PDF 9.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of PDF documents. When parsing shading
nvd
CVE-2018-14442P3CRITICALCVSS 9.8fixed in 9.22018-07-20
CVE-2018-14442 [CRITICAL] CWE-416 CVE-2018-14442: Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Ex
Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs.
nvd
CVE-2023-39542P3HIGHCVSS 8.8v12.1.3.153562023-11-27
CVE-2023-39542 [HIGH] CWE-73 CVE-2023-39542: A code execution vulnerability exists in the Javascript saveAs API of Foxit Reader 12.1.3.15356. A s
A code execution vulnerability exists in the Javascript saveAs API of Foxit Reader 12.1.3.15356. A specially crafted malformed file can create arbitrary files, which can lead to remote code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a speci
nvd
CVE-2017-10952P3HIGHCVSS 8.8v8.2.0.20512017-08-29
CVE-2017-10952 [HIGH] CWE-693 CVE-2017-10952: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.2.0.2051. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the saveAs JavaScript function. The issue results from the lack o
nvd
CVE-2018-9951P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-9951 [HIGH] CWE-416 CVE-2018-9951: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of CPDF_Object objects. The issue results from the la
nvd
CVE-2019-17139P3HIGHCVSS 8.8≤ 9.6.0.251142019-10-25
CVE-2019-17139 [HIGH] CWE-787 CVE-2019-17139: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of Javascript in the HTML2PDF plugin. The issu
nvd
CVE-2020-26539P3CRITICALCVSS 9.8fixed in 10.12020-10-02
CVE-2020-26539 [CRITICAL] CWE-416 CVE-2020-26539: An issue was discovered in Foxit Reader and PhantomPDF before 10.1. When there is a multiple interpr
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. When there is a multiple interpretation error for /V (in the Additional Action and Field dictionaries), a use-after-free can occur with resultant remote code execution (or an information leak).
nvd
CVE-2017-10953P3HIGHCVSS 8.8v8.3.0.148782017-10-31
CVE-2017-10953 [HIGH] CWE-78 CVE-2017-10953: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the gotoURL method. The issue results from the lack of proper val
nvd
CVE-2018-9975P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-9975 [HIGH] CWE-416 CVE-2018-9975: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of shift events. The issue results from the lack of va
nvd
CVE-2018-9944P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-9944 [HIGH] CWE-416 CVE-2018-9944: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the addLink method. The issue results from the lack of validating
nvd
CVE-2018-9966P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-9966 [HIGH] CWE-416 CVE-2018-9966: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Calculate actions of TextBox objects. The issue res
nvd
1 / 19Next →