Foxitsoftware Foxit Reader vulnerabilities

372 known vulnerabilities affecting foxitsoftware/foxit_reader.

Total CVEs
372
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL22HIGH264MEDIUM75LOW11

Vulnerabilities

Page 1 of 19
CVE-2023-35985HIGHCVSS 8.8v12.1.3.153562023-11-27
CVE-2023-35985 [HIGH] CWE-73 CVE-2023-35985: An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Read An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to a failure to properly validate a dangerous extension. A specially crafted malicious file can create files at arbitrary locations, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the mali
nvd
CVE-2023-39542HIGHCVSS 8.8v12.1.3.153562023-11-27
CVE-2023-39542 [HIGH] CWE-73 CVE-2023-39542: A code execution vulnerability exists in the Javascript saveAs API of Foxit Reader 12.1.3.15356. A s A code execution vulnerability exists in the Javascript saveAs API of Foxit Reader 12.1.3.15356. A specially crafted malformed file can create arbitrary files, which can lead to remote code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a speci
nvd
CVE-2023-38573HIGHCVSS 8.8v12.1.2.153562023-11-27
CVE-2023-38573 [HIGH] CWE-416 CVE-2023-38573: A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles a signature field A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles a signature field. A specially crafted Javascript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malici
nvd
CVE-2023-41257HIGHCVSS 8.8v12.1.3.153562023-11-27
CVE-2023-41257 [HIGH] CWE-843 CVE-2023-41257: A type confusion vulnerability exists in the way Foxit Reader 12.1.2.15356 handles field value prope A type confusion vulnerability exists in the way Foxit Reader 12.1.2.15356 handles field value properties. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to
nvd
CVE-2023-32616HIGHCVSS 8.8v12.1.2.153562023-11-27
CVE-2023-32616 [HIGH] CWE-416 CVE-2023-32616: A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles 3D annotations. A A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles 3D annotations. A specially crafted Javascript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious
nvd
CVE-2023-40194HIGHCVSS 8.8v12.1.3.153562023-11-27
CVE-2023-40194 [HIGH] CWE-73 CVE-2023-40194: An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Read An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to mistreatment of whitespace characters. A specially crafted malicious file can create files at arbitrary locations, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to t
nvd
CVE-2022-43310HIGHCVSS 7.8fixed in 11.2.118.515692022-11-09
CVE-2022-43310 [HIGH] CWE-427 CVE-2022-43310: An Uncontrolled Search Path Element in Foxit Software released Foxit Reader v11.2.118.51569 allows a An Uncontrolled Search Path Element in Foxit Software released Foxit Reader v11.2.118.51569 allows attackers to escalate privileges when searching for DLL libraries without specifying an absolute path.
nvd
CVE-2021-38568CRITICALCVSS 9.8fixed in 10.1.42021-08-11
CVE-2021-38568 [CRITICAL] CWE-787 CVE-2021-38568: An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows memory corruption du An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows memory corruption during conversion of a PDF document to a different document format.
nvd
CVE-2021-38574CRITICALCVSS 9.8fixed in 10.1.42021-08-11
CVE-2021-38574 [CRITICAL] CWE-89 CVE-2021-38574: An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via cr An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.
nvd
CVE-2021-33793CRITICALCVSS 9.8fixed in 10.1.42021-08-11
CVE-2021-33793 [CRITICAL] CWE-787 CVE-2021-33793: Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write because the Cros Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write because the Cross-Reference table is mishandled during Office document conversion.
nvd
CVE-2021-38570CRITICALCVSS 9.1fixed in 10.1.42021-08-11
CVE-2021-38570 [CRITICAL] CWE-59 CVE-2021-38570: An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows attackers to delete An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows attackers to delete arbitrary files (during uninstallation) via a symlink.
nvd
CVE-2021-33794CRITICALCVSS 9.1fixed in 10.1.42021-08-11
CVE-2021-33794 [CRITICAL] CVE-2021-33794: Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 allow information disclosure or an applicati Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 allow information disclosure or an application crash after mishandling the Tab key during XFA form interaction.
nvd
CVE-2021-38573CRITICALCVSS 9.8fixed in 10.1.42021-08-11
CVE-2021-38573 [CRITICAL] CVE-2021-38573: An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not validated.
nvd
CVE-2021-38572CRITICALCVSS 9.8fixed in 10.1.42021-08-11
CVE-2021-38572 [CRITICAL] CVE-2021-38572: An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because the extractPages pathname is not validated.
nvd
CVE-2021-38571HIGHCVSS 7.8fixed in 10.1.42021-08-11
CVE-2021-38571 [HIGH] CWE-427 CVE-2021-38571: An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka C An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and CNVD-C-2021-68502.
nvd
CVE-2021-38569HIGHCVSS 7.5fixed in 10.1.42021-08-11
CVE-2021-38569 [HIGH] CWE-674 CVE-2021-38569: An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows stack consumption vi An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows stack consumption via recursive function calls during the handling of XFA forms or link objects.
nvd
CVE-2021-33792HIGHCVSS 7.8fixed in 10.1.42021-07-09
CVE-2021-33792 [HIGH] CWE-787 CVE-2021-33792: Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write via a crafted /S Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write via a crafted /Size key in the Trailer dictionary.
nvd
CVE-2021-33795MEDIUMCVSS 5.5fixed in 10.1.42021-07-09
CVE-2021-33795 [MEDIUM] CWE-755 CVE-2021-33795: Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 produce incorrect PDF document signatures be Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 produce incorrect PDF document signatures because the certificate name, document owner, and signature author are mishandled.
nvd
CVE-2021-31476HIGHCVSS 7.8≤ 10.1.3.375982021-06-16
CVE-2021-31476 [HIGH] CWE-843 CVE-2021-31476: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.3.37598. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of XFA templates. The issue results from the la
nvd
CVE-2021-21822HIGHCVSS 8.8v10.1.3.375982021-05-10
CVE-2021-21822 [HIGH] CWE-416 CVE-2021-21822: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, versi A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.3.37598. A specially crafted PDF document can trigger the reuse of previously free memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening a malicious file or site to trigger this vulnerability if the
nvd
1 / 19Next →