Foxitsoftware Foxit Reader vulnerabilities
372 known vulnerabilities affecting foxitsoftware/foxit_reader.
Total CVEs
372
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL22HIGH264MEDIUM75LOW11
Vulnerabilities
Page 18 of 19
CVE-2018-19342P4HIGHCVSS 7.1v9.3.0.108262018-11-17
CVE-2018-19342 [HIGH] CWE-125 CVE-2018-19342: The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.108
The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Read Access Violation starting at U3DBrowser+0x000000000000347a" issue.
nvd
CVE-2018-19347P4HIGHCVSS 7.1v9.3.0.108262018-11-17
CVE-2018-19347 [HIGH] CWE-125 CVE-2018-19347: The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.108
The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Data from Faulting Address controls Branch Selection starting at U3DBrowser!PlugInMain+0x00000000000d11bb" issue.
nvd
CVE-2018-19346P4HIGHCVSS 7.1v9.3.0.108262018-11-17
CVE-2018-19346 [HIGH] CWE-125 CVE-2018-19346: The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.108
The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Data from Faulting Address controls Branch Selection starting at U3DBrowser!PlugInMain+0x00000000000d11ea" issue.
nvd
CVE-2018-19344P4HIGHCVSS 7.1v9.3.0.108262018-11-17
CVE-2018-19344 [HIGH] CWE-125 CVE-2018-19344: The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.108
The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Data from Faulting Address may be used as a return value starting at U3DBrowser!PlugInMain+0x0000000000031a75" is
nvd
CVE-2018-19341P4HIGHCVSS 7.1v9.3.0.108262018-11-17
CVE-2018-19341 [HIGH] CWE-125 CVE-2018-19341: The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.108
The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Read Access Violation near NULL starting at FoxitReader!std::basic_ostream >::operator<<+0x0000000000087906" issu
nvd
CVE-2018-19345P4HIGHCVSS 7.1v9.3.0.108262018-11-17
CVE-2018-19345 [HIGH] CWE-125 CVE-2018-19345: The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.108
The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Read Access Violation near NULL starting at U3DBrowser!PlugInMain+0x0000000000053f8b" issue.
nvd
CVE-2018-19343P4HIGHCVSS 7.1v9.3.0.108262018-11-17
CVE-2018-19343 [HIGH] CWE-125 CVE-2018-19343: The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.108
The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read), obtain sensitive information, or possibly have unspecified other impact via a U3D sample because of a "Data from Faulting Address controls Code Flow starting at U3DBrowser!Plu
nvd
CVE-2018-18688P4MEDIUMCVSS 5.3v9.4v9.1.0+1 more2021-01-07
CVE-2018-18688 [MEDIUM] CWE-347 CVE-2018-18688: The Portable Document Format (PDF) specification does not provide any information regarding the conc
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates are displayed to the user witho
nvd
CVE-2019-5007P4HIGHCVSS 7.1fixed in 9.42019-01-03
CVE-2019-5007 [HIGH] CWE-125 CVE-2019-5007: An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. It is an Out-of-Bounds
An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. It is an Out-of-Bounds Read Information Disclosure and crash due to a NULL pointer dereference when reading TIFF data during TIFF parsing.
nvd
CVE-2015-3633P4MEDIUMCVSS 5.0≤ 7.1.3.320v7.1.0.3062015-05-01
CVE-2015-3633 [MEDIUM] CWE-119 CVE-2015-3633: Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denia
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via vectors related to digital signatures.
nvd
CVE-2017-6883P4MEDIUMCVSS 4.7≤ 8.2.0.20512017-03-14
CVE-2017-6883 [MEDIUM] CWE-125 CVE-2017-6883: The ConvertToPDF plugin in Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 on Windows, when th
The ConvertToPDF plugin in Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image. The vulnerability could lead to information disclosure; an attacker can leverage this in conjunction with
nvd
CVE-2020-28203P4MEDIUMCVSS 5.5fixed in 10.1.0.375272020-12-15
CVE-2020-28203 [MEDIUM] CWE-476 CVE-2020-28203: An issue was discovered in Foxit Reader and PhantomPDF 10.1.0.37527 and earlier. There is a null poi
An issue was discovered in Foxit Reader and PhantomPDF 10.1.0.37527 and earlier. There is a null pointer access/dereference while opening a crafted PDF file, leading the application to crash (denial of service).
nvd
CVE-2021-33795P4MEDIUMCVSS 5.5fixed in 10.1.42021-07-09
CVE-2021-33795 [MEDIUM] CWE-755 CVE-2021-33795: Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 produce incorrect PDF document signatures be
Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 produce incorrect PDF document signatures because the certificate name, document owner, and signature author are mishandled.
nvd
CVE-2012-4759P4MEDIUMCVSS 6.9v5.3.1.06062012-09-06
CVE-2012-4759 [MEDIUM] CVE-2012-4759: Untrusted search path vulnerability in facebook_plugin.fpi in the Facebook plug-in in Foxit Reader 5
Untrusted search path vulnerability in facebook_plugin.fpi in the Facebook plug-in in Foxit Reader 5.3.1.0606 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .pdf file. NOTE: some of these details are obtained from third party information.
nvd
CVE-2020-26536P4MEDIUMCVSS 5.5fixed in 10.12020-10-02
CVE-2020-26536 [MEDIUM] CWE-476 CVE-2020-26536: An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is a NULL pointer derefere
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is a NULL pointer dereference via a crafted PDF document.
nvd
CVE-2021-27263P4LOWCVSS 3.3≤ 10.1.0.375272021-03-30
CVE-2021-27263 [LOW] CWE-125 CVE-2021-27263: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in PDF files. Th
nvd
CVE-2018-19390P4MEDIUMCVSS 5.5v9.3.0.108262018-11-20
CVE-2018-19390 [MEDIUM] CWE-125 CVE-2018-19390: FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (Br
FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (Break instruction exception and application crash) via TIFF data because of a ConvertToPDF_x86!ConnectedPDF::ConnectedPDFSDK::FCP_SendEmailNotification issue.
nvd
CVE-2018-19389P4MEDIUMCVSS 5.5v9.3.0.108262018-11-20
CVE-2018-19389 [MEDIUM] CWE-125 CVE-2018-19389: FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (Br
FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (Break instruction exception and application crash) via BMP data because of a ConvertToPDF_x86!ConnectedPDF::ConnectedPDFSDK::FCP_SendEmailNotification issue.
nvd
CVE-2019-5006P4MEDIUMCVSS 5.5fixed in 9.42019-01-03
CVE-2019-5006 [MEDIUM] CWE-476 CVE-2019-5006: An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. It is a NULL pointer d
An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. It is a NULL pointer dereference during PDF parsing.
nvd
CVE-2021-31446P4LOWCVSS 3.3≤ 10.1.3.375982021-05-07
CVE-2021-31446 [LOW] CWE-125 CVE-2021-31446: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in PDF files. The is
nvd