Foxitsoftware Foxit Reader vulnerabilities
372 known vulnerabilities affecting foxitsoftware/foxit_reader.
Total CVEs
372
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL22HIGH264MEDIUM75LOW11
Vulnerabilities
Page 13 of 19
CVE-2017-8454P3HIGHCVSS 8.8≤ 8.2.0.20512017-05-03
CVE-2017-8454 [HIGH] CWE-125 CVE-2017-8454: Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote
Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document.
nvd
CVE-2017-8453P3HIGHCVSS 8.8≤ 8.2.0.20512017-05-03
CVE-2017-8453 [HIGH] CWE-125 CVE-2017-8453: Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote
Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document.
nvd
CVE-2016-4059P3HIGHCVSS 7.8≤ 7.3.0.1182016-04-22
CVE-2016-4059 [HIGH] CVE-2016-4059: Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote at
Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via a crafted FlateDecode stream in a PDF document.
nvd
CVE-2017-10994P3HIGHCVSS 7.3≤ 8.3.0.148782017-07-07
CVE-2017-10994 [HIGH] CWE-123 CVE-2017-10994: Foxit Reader before 8.3.1 and PhantomPDF before 8.3.1 have an Arbitrary Write vulnerability, which a
Foxit Reader before 8.3.1 and PhantomPDF before 8.3.1 have an Arbitrary Write vulnerability, which allows remote attackers to execute arbitrary code via a crafted document.
nvd
CVE-2019-6760P3HIGHCVSS 7.8≤ 9.4.1.168282019-06-03
CVE-2019-6760 [HIGH] CWE-787 CVE-2019-6760: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.4.16811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within ConvertToPDF_x86.dll. The issue results from the lack of proper vali
nvd
CVE-2019-6759P3HIGHCVSS 7.8≤ 9.4.1.168282019-06-03
CVE-2019-6759 [HIGH] CWE-787 CVE-2019-6759: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.3.10826. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within ConvertToPDF_x86.dll. The issue results from the lack of proper vali
nvd
CVE-2019-6765P3HIGHCVSS 7.8≤ 9.4.1.168282019-06-03
CVE-2019-6765 [HIGH] CWE-125 CVE-2019-6765: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the conversion of HTML files to PDF. The issue results from th
nvd
CVE-2019-6764P3HIGHCVSS 7.8≤ 9.4.1.168282019-06-03
CVE-2019-6764 [HIGH] CWE-787 CVE-2019-6764: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XFA Template objects. The issue results from the
nvd
CVE-2019-6755P3HIGHCVSS 7.8≤ 9.4.1.168282019-06-03
CVE-2019-6755 [HIGH] CWE-787 CVE-2019-6755: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.3.10826. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within ConvertToPDF_x86.dll. The issue results from the lack of proper vali
nvd
CVE-2018-10302P3HIGHCVSS 7.8fixed in 9.12018-04-23
CVE-2018-10302 [HIGH] CWE-416 CVE-2018-10302: A use-after-free in Foxit Reader before 9.1 and PhantomPDF before 9.1 allows remote attackers to exe
A use-after-free in Foxit Reader before 9.1 and PhantomPDF before 9.1 allows remote attackers to execute arbitrary code, aka iDefense ID V-jyb51g3mv9.
nvd
CVE-2021-31442P3HIGHCVSS 7.8≤ 10.1.3.375982021-05-07
CVE-2021-31442 [HIGH] CWE-787 CVE-2021-31442: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects in PDF files. The issue results from
nvd
CVE-2021-27270P3HIGHCVSS 7.8≤ 10.1.0.375272021-03-30
CVE-2021-27270 [HIGH] CWE-125 CVE-2021-27270: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPEG2000 images. The issue results from the l
nvd
CVE-2021-27261P3HIGHCVSS 7.8≤ 10.1.0.375272021-03-30
CVE-2021-27261 [HIGH] CWE-125 CVE-2021-27261: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects in PDF files. The issue results
nvd
CVE-2021-27269P3HIGHCVSS 7.8≤ 10.1.0.375272021-03-30
CVE-2021-27269 [HIGH] CWE-787 CVE-2021-27269: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects in PDF files. The issue results
nvd
CVE-2021-33793P3CRITICALCVSS 9.8fixed in 10.1.42021-08-11
CVE-2021-33793 [CRITICAL] CWE-787 CVE-2021-33793: Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write because the Cros
Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write because the Cross-Reference table is mishandled during Office document conversion.
nvd
CVE-2018-18933P3CRITICALCVSS 9.1v9.3.0.108262018-11-05
CVE-2018-18933 [CRITICAL] CWE-125 CVE-2018-18933: The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.108
The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Read Access Violation near NULL starting at FoxitReader!safe_vsnprintf+0x00000000002c4330" issue.
nvd
CVE-2016-4063P3HIGHCVSS 7.8≤ 7.3.0.1182016-04-22
CVE-2016-4063 [HIGH] CVE-2016-4063: Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote at
Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via an object with a revision number of -1 in a PDF document.
nvd
CVE-2021-33794P3CRITICALCVSS 9.1fixed in 10.1.42021-08-11
CVE-2021-33794 [CRITICAL] CVE-2021-33794: Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 allow information disclosure or an applicati
Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 allow information disclosure or an application crash after mishandling the Tab key during XFA form interaction.
nvd
CVE-2020-26537P3CRITICALCVSS 9.8fixed in 10.12020-10-02
CVE-2020-26537 [CRITICAL] CWE-787 CVE-2020-26537: An issue was discovered in Foxit Reader and PhantomPDF before 10.1. In a certain Shading calculation
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. In a certain Shading calculation, the number of outputs is unequal to the number of color components in a color space. This causes an out-of-bounds write.
nvd
CVE-2021-38568P3CRITICALCVSS 9.8fixed in 10.1.42021-08-11
CVE-2021-38568 [CRITICAL] CWE-787 CVE-2021-38568: An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows memory corruption du
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows memory corruption during conversion of a PDF document to a different document format.
nvd