cbcvebase.

Foxitsoftware Foxit Reader vulnerabilities

372 known vulnerabilities affecting foxitsoftware/foxit_reader.

Total CVEs
372
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL22HIGH264MEDIUM75LOW11

Vulnerabilities

Page 10 of 19
CVE-2017-14830P3HIGHCVSS 8.8v8.3.1.211552017-12-20
CVE-2017-14830 [HIGH] CWE-843 CVE-2017-14830: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the setFocus method of XFAScriptObject objects. The issue result
nvd
CVE-2017-14829P3HIGHCVSS 8.8v8.3.1.211552017-12-20
CVE-2017-14829 [HIGH] CWE-843 CVE-2017-14829: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the openList method of XFAScriptObject objects. The issue result
nvd
CVE-2017-16578P3HIGHCVSS 8.8v8.3.2.250132017-12-20
CVE-2017-16578 [HIGH] CWE-843 CVE-2017-16578: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.2.25013. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the picture elements within XFA forms. The issue results from th
nvd
CVE-2017-16571P3HIGHCVSS 8.8v8.3.1.211552017-12-20
CVE-2017-16571 [HIGH] CWE-843 CVE-2017-16571: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of references to the app object from FormCalc. The
nvd
CVE-2016-3740P3HIGHCVSS 7.8v7.3.4.3112017-04-04
CVE-2016-3740 [HIGH] CWE-119 CVE-2016-3740: Heap-based buffer overflow in the CreateFXPDFConvertor function in ConvertToPdf_x86.dll in Foxit Rea Heap-based buffer overflow in the CreateFXPDFConvertor function in ConvertToPdf_x86.dll in Foxit Reader 7.3.4.311 allows remote attackers to execute arbitrary code via a large SamplesPerPixel value in a crafted TIFF image that is mishandled during PDF conversion. This is fixed in 8.0.
nvd
CVE-2008-1104P3CRITICALCVSS 9.3≤ 2.3v2.0+1 more2008-05-21
CVE-2008-1104 [CRITICAL] CWE-119 CVE-2008-1104: Stack-based buffer overflow in Foxit Reader before 2.3 build 2912 allows user-assisted remote attack Stack-based buffer overflow in Foxit Reader before 2.3 build 2912 allows user-assisted remote attackers to execute arbitrary code via a crafted PDF file, related to the util.printf JavaScript function and floating point specifiers in format strings.
nvd
CVE-2021-38574P3CRITICALCVSS 9.8fixed in 10.1.42021-08-11
CVE-2021-38574 [CRITICAL] CWE-89 CVE-2021-38574: An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via cr An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.
nvd
CVE-2020-13560P3HIGHCVSS 8.8v10.1.0.37527vFoxit Reader Version: 10.1.0.375272020-12-22
CVE-2020-13560 [HIGH] CWE-416 CVE-2020-13560: A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser
nvd
CVE-2018-11622P3HIGHCVSS 8.8≤ 9.1.0.50962018-07-31
CVE-2018-11622 [HIGH] CWE-787 CVE-2018-11622: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within ConvertToPDF_x86.dll. The issue results from the lack of proper v
nvd
CVE-2018-9982P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-9982 [HIGH] CWE-787 CVE-2018-9982: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of the Texture Width in U3D files. The issue results f
nvd
CVE-2018-10473P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-10473 [HIGH] CWE-787 CVE-2018-10473: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D CLOD Base Mesh Continuation structures. The i
nvd
CVE-2018-10491P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-10491 [HIGH] CWE-787 CVE-2018-10491: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Bone Weight Modifier structures. The issue re
nvd
CVE-2018-10483P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-10483 [HIGH] CWE-787 CVE-2018-10483: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Clod Progressive Mesh objects. The issue resu
nvd
CVE-2018-10477P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-10477 [HIGH] CWE-787 CVE-2018-10477: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Chain Index objects. The issue results from t
nvd
CVE-2018-10474P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-10474 [HIGH] CWE-787 CVE-2018-10474: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Shading objects. The issue results from the l
nvd
CVE-2018-10489P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-10489 [HIGH] CWE-787 CVE-2018-10489: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Clod Progressive Mesh Declaration structures.
nvd
CVE-2018-10303P3HIGHCVSS 8.8fixed in 9.12018-04-23
CVE-2018-10303 [HIGH] CWE-416 CVE-2018-10303: A use-after-free in Foxit Reader before 9.1 and PhantomPDF before 9.1 allows remote attackers to exe A use-after-free in Foxit Reader before 9.1 and PhantomPDF before 9.1 allows remote attackers to execute arbitrary code, aka iDefense ID V-y0nqfutlf3.
nvd
CVE-2011-0332P3CRITICALCVSS 9.3≤ 4.3v2.0+12 more2011-02-25
CVE-2011-0332 [CRITICAL] CWE-189 CVE-2011-0332: Integer overflow in Foxit Reader before 4.3.1.0218 and Foxit Phantom before 2.3.3.1112 allows remote Integer overflow in Foxit Reader before 4.3.1.0218 and Foxit Phantom before 2.3.3.1112 allows remote attackers to execute arbitrary code via crafted ICC chunks in a PDF file, which triggers a heap-based buffer overflow.
nvd
CVE-2020-17416P3HIGHCVSS 7.8≤ 10.0.1.358112020-10-13
CVE-2020-17416 [HIGH] CWE-787 CVE-2020-17416: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.0.0.35798. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPEG2000 images. The issue results from the lack
nvd
CVE-2009-0191P3CRITICALCVSS 9.3v2.3v3.0+1 more2009-03-10
CVE-2009-0191 [CRITICAL] CWE-94 CVE-2009-0191: Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 3.0.2009.1301, does not prop Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 3.0.2009.1301, does not properly handle a JBIG2 symbol dictionary segment with zero new symbols, which allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a dereference of an uninitialized memory location.
nvd
Foxitsoftware Foxit Reader vulnerabilities | cvebase