Foxitsoftware Foxit Reader vulnerabilities
372 known vulnerabilities affecting foxitsoftware/foxit_reader.
Total CVEs
372
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL22HIGH264MEDIUM75LOW11
Vulnerabilities
Page 11 of 19
CVE-2015-3632P4MEDIUMCVSS 4.3PoC≤ 7.1.3.3202015-05-01
CVE-2015-3632 [MEDIUM] CWE-119 CVE-2015-3632: Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denia
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted GIF in a PDF file.
nvd
CVE-2020-26535P3CRITICALCVSS 9.8fixed in 10.12020-10-02
CVE-2020-26535 [CRITICAL] CWE-787 CVE-2020-26535: An issue was discovered in Foxit Reader and PhantomPDF before 10.1. If TslAlloc attempts to allocate
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. If TslAlloc attempts to allocate thread local storage but obtains an unacceptable index value, V8 throws an exception that leads to a write access violation (and read access violation).
nvd
CVE-2021-31476P3HIGHCVSS 7.8≤ 10.1.3.375982021-06-16
CVE-2021-31476 [HIGH] CWE-843 CVE-2021-31476: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.3.37598. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of XFA templates. The issue results from the la
nvd
CVE-2018-3842P3HIGHCVSS 8.8v9.0.1.10492018-04-19
CVE-2018-3842 [HIGH] CWE-824 CVE-2018-3842: An exploitable use of an uninitialized pointer vulnerability exists in the JavaScript engine in Foxi
An exploitable use of an uninitialized pointer vulnerability exists in the JavaScript engine in Foxit PDF Reader version 9.0.1.1049. A specially crafted PDF document can lead to a dereference of an uninitialized pointer which, if under attacker control, can result in arbitrary code execution. An attacker needs to trick the user to open a malicious file
nvd
CVE-2020-13547P3HIGHCVSS 8.8v10.0.0.37527vFoxit Reader Version: 10.1.0.375272020-12-22
CVE-2020-13547 [HIGH] CWE-843 CVE-2020-13547: A type confusion vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader,
A type confusion vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger an improper use of an object, resulting in memory corruption and arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability.
nvd
CVE-2020-13570P3HIGHCVSS 8.8v10.1.0.37527vFoxit Reader Version: 10.1.0.375272020-12-22
CVE-2020-13570 [HIGH] CWE-416 CVE-2020-13570: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, versi
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger the reuse of previously free memory which can lead to arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser pl
nvd
CVE-2021-21822P3HIGHCVSS 8.8v10.1.3.37598vFoxit Reader 10.1.3.375982021-05-10
CVE-2021-21822 [HIGH] CWE-416 CVE-2021-21822: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, versi
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.3.37598. A specially crafted PDF document can trigger the reuse of previously free memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening a malicious file or site to trigger this vulnerability if the
nvd
CVE-2020-26534P3CRITICALCVSS 9.8fixed in 10.12020-10-02
CVE-2020-26534 [CRITICAL] CWE-416 CVE-2020-26534: An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Field::ClearItems and Field::DeleteOptions, during AcroForm JavaScript execution.
nvd
CVE-2020-10913P3HIGHCVSS 7.8≤ 9.7.1.295112020-04-22
CVE-2020-10913 [HIGH] CWE-843 CVE-2020-10913: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the OCRAndExportToExcel command of the commun
nvd
CVE-2021-38573P3CRITICALCVSS 9.8fixed in 10.1.42021-08-11
CVE-2021-38573 [CRITICAL] CVE-2021-38573: An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not validated.
nvd
CVE-2021-38572P3CRITICALCVSS 9.8fixed in 10.1.42021-08-11
CVE-2021-38572 [CRITICAL] CVE-2021-38572: An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because the extractPages pathname is not validated.
nvd
CVE-2018-3853P3HIGHCVSS 8.8v9.0.1.10492018-06-04
CVE-2018-3853 [HIGH] CWE-416 CVE-2018-3853: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software Foxit
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software Foxit PDF Reader version 9.0.1.1049. A specially crafted PDF document can trigger a previously freed object in memory to be reused resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability
nvd
CVE-2015-2789P4MEDIUMCVSS 4.4PoCv6.1v6.1.2+5 more2015-03-30
CVE-2015-2789 [MEDIUM] CVE-2015-2789: Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugi
Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.1 through 7.0.6.1126 allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.
nvd
CVE-2019-6769P3HIGHCVSS 7.8≤ 9.4.1.168282019-06-03
CVE-2019-6769 [HIGH] CWE-416 CVE-2019-6769: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the removeField method when processing AcroForms. The issue result
nvd
CVE-2019-6767P3HIGHCVSS 7.8≤ 9.4.1.168282019-06-03
CVE-2019-6767 [HIGH] CWE-416 CVE-2019-6767: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the removeField method when processing AcroForms. The issue result
nvd
CVE-2021-31449P3HIGHCVSS 7.8≤ 10.1.3.375982021-05-07
CVE-2021-31449 [HIGH] CWE-415 CVE-2021-31449: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in PDF files. The issue res
nvd
CVE-2021-31451P3HIGHCVSS 7.8≤ 10.1.3.375982021-05-07
CVE-2021-31451 [HIGH] CWE-416 CVE-2021-31451: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the l
nvd
CVE-2021-31453P3HIGHCVSS 7.8≤ 10.1.3.375982021-05-07
CVE-2021-31453 [HIGH] CWE-416 CVE-2021-31453: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of XFA Forms. The issue results from the lack of va
nvd
CVE-2021-31441P3HIGHCVSS 7.8≤ 10.1.3.375982021-05-07
CVE-2021-31441 [HIGH] CWE-416 CVE-2021-31441: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the l
nvd
CVE-2021-31450P3HIGHCVSS 7.8≤ 10.1.3.375982021-05-07
CVE-2021-31450 [HIGH] CWE-416 CVE-2021-31450: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of XFA forms. The issue results from the lack of va
nvd