cbcvebase.

Foxitsoftware Foxit Reader vulnerabilities

372 known vulnerabilities affecting foxitsoftware/foxit_reader.

Total CVEs
372
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL22HIGH264MEDIUM75LOW11

Vulnerabilities

Page 5 of 19
CVE-2017-10945P3HIGHCVSS 8.8v8.3.0.148782017-10-31
CVE-2017-10945 [HIGH] CWE-416 CVE-2017-10945: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the app.alert function. The issue results from the lack of valid
nvd
CVE-2023-38573P3HIGHCVSS 8.8v12.1.2.153562023-11-27
CVE-2023-38573 [HIGH] CWE-416 CVE-2023-38573: A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles a signature field A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles a signature field. A specially crafted Javascript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malici
nvd
CVE-2023-32616P3HIGHCVSS 8.8v12.1.2.153562023-11-27
CVE-2023-32616 [HIGH] CWE-416 CVE-2023-32616: A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles 3D annotations. A A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles 3D annotations. A specially crafted Javascript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious
nvd
CVE-2023-41257P3HIGHCVSS 8.8v12.1.3.153562023-11-27
CVE-2023-41257 [HIGH] CWE-843 CVE-2023-41257: A type confusion vulnerability exists in the way Foxit Reader 12.1.2.15356 handles field value prope A type confusion vulnerability exists in the way Foxit Reader 12.1.2.15356 handles field value properties. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to
nvd
CVE-2020-17417P3HIGHCVSS 7.8≤ 10.0.1.358112020-10-13
CVE-2020-17417 [HIGH] CWE-416 CVE-2020-17417: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.0.1.35811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the Annotation objects. The issue results from t
nvd
CVE-2012-4337P3CRITICALCVSS 9.3≤ 5.1.4.0104v2.0+17 more2012-08-23
CVE-2012-4337 [CRITICAL] CVE-2012-4337: Foxit Reader before 5.3 on Windows XP and Windows 7 allows remote attackers to execute arbitrary cod Foxit Reader before 5.3 on Windows XP and Windows 7 allows remote attackers to execute arbitrary code via a PDF document with a crafted attachment that triggers calculation of a negative number during processing of cross references.
nvd
CVE-2017-17557P3HIGHCVSS 8.8fixed in 9.12018-04-24
CVE-2017-17557 [HIGH] CWE-119 CVE-2017-17557: In Foxit Reader before 9.1 and Foxit PhantomPDF before 9.1, a flaw exists within the parsing of the In Foxit Reader before 9.1 and Foxit PhantomPDF before 9.1, a flaw exists within the parsing of the BITMAPINFOHEADER record in BMP files. The issue results from the lack of proper validation of the biSize member, which can result in a heap based buffer overflow. An attacker can leverage this to execute code in the context of the current process.
nvd
CVE-2018-9943P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-9943 [HIGH] CWE-704 CVE-2018-9943: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the openList method. The issue results from the la
nvd
CVE-2018-9937P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-9937 [HIGH] CWE-704 CVE-2018-9937: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of subform elements. The issue results from the lack o
nvd
CVE-2018-9939P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-9939 [HIGH] CWE-704 CVE-2018-9939: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of layout elements. The issue results from the lack o
nvd
CVE-2018-9940P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-9940 [HIGH] CWE-704 CVE-2018-9940: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the layout sheet attribute. The issue results from
nvd
CVE-2018-9949P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-9949 [HIGH] CWE-122 CVE-2018-9949: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIFF files. The issue results from the lack of prop
nvd
CVE-2018-9942P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-9942 [HIGH] CWE-704 CVE-2018-9942: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the record remove method. The issue results from t
nvd
CVE-2018-9941P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-9941 [HIGH] CWE-704 CVE-2018-9941: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the record append method. The issue results from t
nvd
CVE-2018-9938P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-9938 [HIGH] CWE-704 CVE-2018-9938: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the absPageSpan method. The issue results from the
nvd
CVE-2018-14293P3HIGHCVSS 8.8≤ 9.1.0.50962018-07-31
CVE-2018-14293 [HIGH] CWE-416 CVE-2018-14293: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.1.0.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF documents. By manipulating a document's elemen
nvd
CVE-2018-14305P3HIGHCVSS 8.8≤ 9.1.0.50962018-07-31
CVE-2018-14305 [HIGH] CWE-416 CVE-2018-14305: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PolyLine annotations. By manipulating a documen
nvd
CVE-2018-14303P3HIGHCVSS 8.8≤ 9.1.0.50962018-07-31
CVE-2018-14303 [HIGH] CWE-416 CVE-2018-14303: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of StrikeOut annotations. By manipulating a docume
nvd
CVE-2018-14307P3HIGHCVSS 8.8≤ 9.1.0.50962018-07-31
CVE-2018-14307 [HIGH] CWE-416 CVE-2018-14307: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of Link objects. By manipulating a document's elem
nvd
CVE-2018-14296P3HIGHCVSS 8.8≤ 9.1.0.50962018-07-31
CVE-2018-14296 [HIGH] CWE-416 CVE-2018-14296: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of Circle annotations. By manipulating a document'
nvd
Foxitsoftware Foxit Reader vulnerabilities | cvebase