cbcvebase.

Foxitsoftware Foxit Reader vulnerabilities

372 known vulnerabilities affecting foxitsoftware/foxit_reader.

Total CVEs
372
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL22HIGH264MEDIUM75LOW11

Vulnerabilities

Page 17 of 19
CVE-2017-16574P4MEDIUMCVSS 6.5v8.3.1.211552017-12-20
CVE-2017-16574 [MEDIUM] CWE-125 CVE-2017-16574: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of Image filters. The issue results from
nvd
CVE-2017-16573P4MEDIUMCVSS 6.5v8.3.1.211552017-12-20
CVE-2017-16573 [MEDIUM] CWE-125 CVE-2017-16573: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of LZWDecode filters. The issue results f
nvd
CVE-2017-16580P4MEDIUMCVSS 6.5v8.3.2.250132017-12-20
CVE-2017-16580 [MEDIUM] CWE-125 CVE-2017-16580: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.2.25013. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the ImageField node of XFA forms. The issue results f
nvd
CVE-2017-14822P4MEDIUMCVSS 6.5v8.3.1.211552017-12-20
CVE-2017-14822 [MEDIUM] CWE-125 CVE-2017-14822: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of the xOsiz member of SIZ markers. The i
nvd
CVE-2017-14821P4MEDIUMCVSS 6.5v8.3.1.211552017-12-20
CVE-2017-14821 [MEDIUM] CWE-125 CVE-2017-14821: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of the xTsiz member of SIZ markers. The i
nvd
CVE-2017-10942P4MEDIUMCVSS 6.5v8.3.0.148782017-10-31
CVE-2017-10942 [MEDIUM] CWE-125 CVE-2017-10942: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the
nvd
CVE-2017-10943P4MEDIUMCVSS 6.5v8.3.0.148782017-10-31
CVE-2017-10943 [MEDIUM] CWE-125 CVE-2017-10943: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the
nvd
CVE-2018-18689P4MEDIUMCVSS 5.3v9.1.0v9.2.0.9297+2 more2021-01-07
CVE-2018-18689 [MEDIUM] CWE-347 CVE-2018-18689: The Portable Document Format (PDF) specification does not provide any information regarding the conc The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations that are not detected by the signature-validation logic. This affects Fox
nvd
CVE-2016-4065P4HIGHCVSS 7.8≤ 7.3.0.1182016-04-22
CVE-2016-4065 [HIGH] CWE-119 CVE-2016-4065: The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 7.3.4 on Windows, when the gflags app The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 7.3.4 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted (1) JPEG, (2) GIF, or (3) BMP image.
nvd
CVE-2016-4060P4HIGHCVSS 7.5≤ 7.3.0.1182016-04-22
CVE-2016-4060 [HIGH] CVE-2016-4060: Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote at Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2019-6773P4MEDIUMCVSS 5.5≤ 9.4.1.168282019-06-03
CVE-2019-6773 [MEDIUM] CWE-416 CVE-2019-6773: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the richValue property of a Field objec
nvd
CVE-2016-4061P4HIGHCVSS 7.5≤ 7.3.0.1182016-04-22
CVE-2016-4061 [HIGH] CWE-20 CVE-2016-4061: Foxit Reader and PhantomPDF before 7.3.4 on Windows allow remote attackers to cause a denial of serv Foxit Reader and PhantomPDF before 7.3.4 on Windows allow remote attackers to cause a denial of service (application crash) via a crafted content stream.
nvd
CVE-2019-6756P4MEDIUMCVSS 5.5≤ 9.4.1.168282019-06-03
CVE-2019-6756 [MEDIUM] CWE-416 CVE-2019-6756: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF 9.4.0.16811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of HTML files. The issue results from t
nvd
CVE-2019-6770P4MEDIUMCVSS 5.5≤ 9.4.1.168282019-06-03
CVE-2019-6770 [MEDIUM] CWE-416 CVE-2019-6770: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the resetForm method when processing AcroForms. The iss
nvd
CVE-2019-6771P4MEDIUMCVSS 5.5≤ 9.4.1.168282019-06-03
CVE-2019-6771 [MEDIUM] CWE-416 CVE-2019-6771: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 2019.010.20098. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the value property of a Field object
nvd
CVE-2019-6758P4MEDIUMCVSS 5.5≤ 9.4.1.168282019-06-03
CVE-2019-6758 [MEDIUM] CWE-416 CVE-2019-6758: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.4.16811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within ConvertToPDF_x86.dll. The issue results from the lack of
nvd
CVE-2019-6772P4MEDIUMCVSS 5.5≤ 9.4.1.168282019-06-03
CVE-2019-6772 [MEDIUM] CWE-416 CVE-2019-6772: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 2019.010.20098. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the removeField method when processing AcroForms. Th
nvd
CVE-2019-6766P4MEDIUMCVSS 5.5≤ 9.4.1.168282019-06-03
CVE-2019-6766 [MEDIUM] CWE-416 CVE-2019-6766: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the removeField method when processing AcroForms. The i
nvd
CVE-2019-6752P4MEDIUMCVSS 5.5≤ 9.4.1.168282019-06-03
CVE-2019-6752 [MEDIUM] CWE-125 CVE-2019-6752: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF 9.3.10826. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF documents. The issue results from
nvd
CVE-2018-19348P4HIGHCVSS 7.1v9.3.0.108262018-11-17
CVE-2018-19348 [HIGH] CWE-125 CVE-2018-19348: The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.108 The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Data from Faulting Address controls Branch Selection starting at U3DBrowser!PlugInMain+0x000000000012dff5" issue.
nvd
Foxitsoftware Foxit Reader vulnerabilities | cvebase