Foxitsoftware Foxit Reader vulnerabilities
372 known vulnerabilities affecting foxitsoftware/foxit_reader.
Total CVEs
372
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL22HIGH264MEDIUM75LOW11
Vulnerabilities
Page 14 of 19
CVE-2016-6169P3HIGHCVSS 7.8≤ 7.3.4.3112018-02-07
CVE-2016-6169 [HIGH] CWE-119 CVE-2016-6169: Heap-based buffer overflow in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows re
Heap-based buffer overflow in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to cause a denial of service (memory corruption and application crash) or potentially execute arbitrary code via the Bezier data in a crafted PDF file.
nvd
CVE-2021-33792P3HIGHCVSS 7.8fixed in 10.1.42021-07-09
CVE-2021-33792 [HIGH] CWE-787 CVE-2021-33792: Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write via a crafted /S
Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write via a crafted /Size key in the Trailer dictionary.
nvd
CVE-2017-8455P3HIGHCVSS 7.8≤ 8.2.0.20512017-05-03
CVE-2017-8455 [HIGH] CWE-125 CVE-2017-8455: Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote
Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document.
nvd
CVE-2009-0690P3CRITICALCVSS 9.3v3.0v3.0.2009.13012009-06-23
CVE-2009-0690 [CRITICAL] CWE-189 CVE-2009-0690: The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 d
The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a negative value for the stream offset in a JPEG2000 (aka JPX) stream, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted PDF fi
nvd
CVE-2009-0691P3CRITICALCVSS 9.3v3.02009-06-23
CVE-2009-0691 [CRITICAL] CWE-399 CVE-2009-0691: The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 d
The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a fatal error during decoding of a JPEG2000 (aka JPX) header, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted PDF file that t
nvd
CVE-2020-35931P3HIGHCVSS 7.8fixed in 10.1.1fixed in 4.1.12020-12-31
CVE-2020-35931 [HIGH] CWE-754 CVE-2020-35931: An issue was discovered in Foxit Reader before 10.1.1 (and before 4.1.1 on macOS) and PhantomPDF bef
An issue was discovered in Foxit Reader before 10.1.1 (and before 4.1.1 on macOS) and PhantomPDF before 9.7.5 and 10.x before 10.1.1 (and before 4.1.1 on macOS). An attacker can spoof a certified PDF document via an Evil Annotation Attack because the products fail to consider a null value for a Subtype entry of the Annotation dictionary, in an increme
nvd
CVE-2020-26540P3HIGHCVSS 7.5fixed in 4.12020-10-02
CVE-2020-26540 [HIGH] CWE-347 CVE-2020-26540: An issue was discovered in Foxit Reader and PhantomPDF before 4.1 on macOS. Because the Hardened Run
An issue was discovered in Foxit Reader and PhantomPDF before 4.1 on macOS. Because the Hardened Runtime protection mechanism is not applied to code signing, code injection (or an information leak) can occur.
nvd
CVE-2017-5556P3HIGHCVSS 8.1v8.1.4.12082017-01-23
CVE-2017-5556 [HIGH] CWE-125 CVE-2017-5556: The ConvertToPDF plugin in Foxit Reader before 8.2 and PhantomPDF before 8.2 on Windows, when the gf
The ConvertToPDF plugin in Foxit Reader before 8.2 and PhantomPDF before 8.2 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG image. The vulnerability could lead to information disclosure; an attacker can leverage this in conjunction with other
nvd
CVE-2022-43310P3HIGHCVSS 7.8fixed in 11.2.118.515692022-11-09
CVE-2022-43310 [HIGH] CWE-427 CVE-2022-43310: An Uncontrolled Search Path Element in Foxit Software released Foxit Reader v11.2.118.51569 allows a
An Uncontrolled Search Path Element in Foxit Software released Foxit Reader v11.2.118.51569 allows attackers to escalate privileges when searching for DLL libraries without specifying an absolute path.
nvd
CVE-2015-8580P3MEDIUMCVSS 6.8≤ 7.2.0.7222015-12-16
CVE-2015-8580 [MEDIUM] CVE-2015-8580: Multiple use-after-free vulnerabilities in the (1) Print method and (2) App object handling in Foxit
Multiple use-after-free vulnerabilities in the (1) Print method and (2) App object handling in Foxit Reader before 7.2.2 and Foxit PhantomPDF before 7.2.2 allow remote attackers to execute arbitrary code via a crafted PDF document.
nvd
CVE-2021-38569P3HIGHCVSS 7.5fixed in 10.1.42021-08-11
CVE-2021-38569 [HIGH] CWE-674 CVE-2021-38569: An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows stack consumption vi
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows stack consumption via recursive function calls during the handling of XFA forms or link objects.
nvd
CVE-2019-13123P3HIGHCVSS 7.5≤ 9.6.0.251142019-09-30
CVE-2019-13123 [HIGH] CWE-674 CVE-2019-13123: Foxit Reader 9.6.0.25114 and earlier has two unique RecursiveCall bugs involving 3 functions exhaust
Foxit Reader 9.6.0.25114 and earlier has two unique RecursiveCall bugs involving 3 functions exhausting available stack memory because of Uncontrolled Recursion in the V8 JavaScript engine (issue 1 of 2).
nvd
CVE-2019-13124P3HIGHCVSS 7.5≤ 9.6.0.251142019-09-30
CVE-2019-13124 [HIGH] CWE-674 CVE-2019-13124: Foxit Reader 9.6.0.25114 and earlier has two unique RecursiveCall bugs involving 3 functions exhaust
Foxit Reader 9.6.0.25114 and earlier has two unique RecursiveCall bugs involving 3 functions exhausting available stack memory because of Uncontrolled Recursion in the V8 JavaScript engine (issue 2 of 2).
nvd
CVE-2019-8342P3HIGHCVSS 7.8v3.1.0.01112019-05-13
CVE-2019-8342 [HIGH] CWE-732 CVE-2019-8342: A Local Privilege Escalation in libqcocoa.dylib in Foxit Reader 3.1.0.0111 on macOS has been discove
A Local Privilege Escalation in libqcocoa.dylib in Foxit Reader 3.1.0.0111 on macOS has been discovered due to an incorrect permission set.
nvd
CVE-2020-26538P3HIGHCVSS 7.8fixed in 10.12020-10-02
CVE-2020-26538 [HIGH] CWE-427 CVE-2020-26538: An issue was discovered in Foxit Reader and PhantomPDF before 10.1. It allows attackers to execute a
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. It allows attackers to execute arbitrary code via a Trojan horse taskkill.exe in the current working directory.
nvd
CVE-2015-8843P3HIGHCVSS 7.4v6.1v6.1.2+8 more2016-04-13
CVE-2015-8843 [HIGH] CWE-119 CVE-2015-8843: The Foxit Cloud Update Service (FoxitCloudUpdateService) in Foxit Reader 6.1 through 6.2.x and 7.x b
The Foxit Cloud Update Service (FoxitCloudUpdateService) in Foxit Reader 6.1 through 6.2.x and 7.x before 7.2.2, when an update to the Cloud plugin is available, allows local users to gain privileges by writing crafted data to a shared memory region, which triggers memory corruption.
nvd
CVE-2018-9971P3MEDIUMCVSS 6.5v9.0.1.1042018-05-17
CVE-2018-9971 [MEDIUM] CWE-125 CVE-2018-9971: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.104. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within ConvertToPDF_x86.dll. The issue results from the lack of
nvd
CVE-2018-9972P3MEDIUMCVSS 6.5≤ 9.0.1.10492018-05-17
CVE-2018-9972 [MEDIUM] CWE-125 CVE-2018-9972: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within ConvertToPDF_x86.dll. The issue results from the lack of
nvd
CVE-2018-9973P3MEDIUMCVSS 6.5≤ 9.0.1.10492018-05-17
CVE-2018-9973 [MEDIUM] CWE-125 CVE-2018-9973: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ePub files. The issue results from the la
nvd
CVE-2018-11621P3MEDIUMCVSS 6.5≤ 9.1.0.50962018-07-31
CVE-2018-11621 [MEDIUM] CWE-125 CVE-2018-11621: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within ConvertToPDF_x86.dll. The issue results from the lack
nvd