Foxitsoftware Phantompdf vulnerabilities
549 known vulnerabilities affecting foxitsoftware/phantompdf.
Total CVEs
549
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL26HIGH438MEDIUM68LOW17
Vulnerabilities
Page 10 of 28
CVE-2018-14301P3HIGHCVSS 8.8≤ 9.1.0.50962018-07-31
CVE-2018-14301 [HIGH] CWE-416 CVE-2018-14301: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of Sound annotations. By manipulating a document's
nvd
CVE-2018-14302P3HIGHCVSS 8.8≤ 9.1.0.50962018-07-31
CVE-2018-14302 [HIGH] CWE-416 CVE-2018-14302: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of Square annotations. By manipulating a document'
nvd
CVE-2018-14306P3HIGHCVSS 8.8≤ 9.1.0.50962018-07-31
CVE-2018-14306 [HIGH] CWE-416 CVE-2018-14306: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of button objects. By manipulating a document's el
nvd
CVE-2018-9981P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-9981 [HIGH] CWE-824 CVE-2018-9981: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of prope
nvd
CVE-2018-10488P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-10488 [HIGH] CWE-122 CVE-2018-10488: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Texture Width structures. The issue results f
nvd
CVE-2020-17410P3HIGHCVSS 7.8≤ 10.0.1.358112020-10-13
CVE-2020-17410 [HIGH] CWE-416 CVE-2020-17410: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.0.0.35798. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of GIF files. The issue results from the lack of
nvd
CVE-2018-17610P3CRITICALCVSS 9.8fixed in 9.32018-09-28
CVE-2018-17610 [CRITICAL] CWE-416 CVE-2018-17610: Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a d
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This relates to one of five distinct types of Annotation objects.
nvd
CVE-2018-17607P3CRITICALCVSS 9.8fixed in 9.32018-09-28
CVE-2018-17607 [CRITICAL] CWE-416 CVE-2018-17607: Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a d
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This relates to one of five distinct types of Annotation objects.
nvd
CVE-2018-17608P3CRITICALCVSS 9.8fixed in 9.32018-09-28
CVE-2018-17608 [CRITICAL] CWE-416 CVE-2018-17608: Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a d
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This relates to one of five distinct types of Annotation objects.
nvd
CVE-2018-17609P3CRITICALCVSS 9.8fixed in 9.32018-09-28
CVE-2018-17609 [CRITICAL] CWE-416 CVE-2018-17609: Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a d
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This relates to one of five distinct types of Annotation objects.
nvd
CVE-2018-17611P3CRITICALCVSS 9.8fixed in 9.32018-09-28
CVE-2018-17611 [CRITICAL] CWE-416 CVE-2018-17611: Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a d
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This relates to one of five distinct types of Annotation objects.
nvd
CVE-2018-5675P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-24
CVE-2018-5675 [HIGH] CWE-787 CVE-2018-5675: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before 9.1 and PhantomPDF before 9.1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of specially crafted pdf f
nvd
CVE-2018-17671P3HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17671 [HIGH] CWE-125 CVE-2018-17671: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the Lower method of a XFA object. The is
nvd
CVE-2018-1176P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-1176 [HIGH] CWE-787 CVE-2018-1176: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ePub files. The issue results from the lack of prop
nvd
CVE-2018-5680P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-24
CVE-2018-5680 [HIGH] CVE-2018-5680: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before 9.1 and PhantomPDF before 9.1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of specially crafted pdf files wit
nvd
CVE-2016-8877P3HIGHCVSS 8.8≤ 8.0.52016-10-31
CVE-2016-8877 [HIGH] CWE-787 CVE-2016-8877: Heap buffer overflow (Out-of-Bounds write) vulnerability in Foxit Reader and PhantomPDF before 8.1 o
Heap buffer overflow (Out-of-Bounds write) vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows allows remote attackers to execute arbitrary code via a crafted JPEG2000 image embedded in a PDF document, aka a "corrupted suffix pattern" issue.
nvd
CVE-2018-11623P3HIGHCVSS 8.8≤ 9.1.0.50962018-07-31
CVE-2018-11623 [HIGH] CWE-843 CVE-2018-11623: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the addAdLayer method. By performing actions in JavaScript, an at
nvd
CVE-2018-14242P3HIGHCVSS 8.8≤ 9.1.0.50962018-07-31
CVE-2018-14242 [HIGH] CWE-843 CVE-2018-14242: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the addField method. By performing actions in JavaScript, an atta
nvd
CVE-2018-17706P3HIGHCVSS 8.8≤ 9.1.0.50962018-10-29
CVE-2018-17706 [HIGH] CWE-787 CVE-2018-17706: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF Phantom PDF 9.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within fxhtml2pdf. The issue results from the lack of prop
nvd
CVE-2018-14247P3HIGHCVSS 8.8≤ 9.1.0.50962018-07-31
CVE-2018-14247 [HIGH] CWE-843 CVE-2018-14247: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the exportAsFDF method. By performing actions in JavaScript, an a
nvd