Foxitsoftware Phantompdf vulnerabilities

549 known vulnerabilities affecting foxitsoftware/phantompdf.

Total CVEs
549
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL26HIGH438MEDIUM68LOW17

Vulnerabilities

Page 11 of 28
CVE-2019-6767HIGHCVSS 7.8≤ 8.3.9.41099≥ 9.0.0, ≤ 9.4.1.168282019-06-03
CVE-2019-6767 [HIGH] CWE-416 CVE-2019-6767: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the removeField method when processing AcroForms. The issue result
nvd
CVE-2019-6752MEDIUMCVSS 5.5≤ 8.3.9.41099≥ 9.0.0, ≤ 9.4.1.168282019-06-03
CVE-2019-6752 [MEDIUM] CWE-125 CVE-2019-6752: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF 9.3.10826. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF documents. The issue results from
nvd
CVE-2019-6770MEDIUMCVSS 5.5≤ 8.3.9.41099≥ 9.0.0, ≤ 9.4.1.168282019-06-03
CVE-2019-6770 [MEDIUM] CWE-416 CVE-2019-6770: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the resetForm method when processing AcroForms. The iss
nvd
CVE-2019-6771MEDIUMCVSS 5.5≤ 8.3.9.41099≥ 9.0.0, ≤ 9.4.1.168282019-06-03
CVE-2019-6771 [MEDIUM] CWE-416 CVE-2019-6771: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 2019.010.20098. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the value property of a Field object
nvd
CVE-2019-6756MEDIUMCVSS 5.5≤ 8.3.9.41099≥ 9.0.0, ≤ 9.4.1.168282019-06-03
CVE-2019-6756 [MEDIUM] CWE-416 CVE-2019-6756: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF 9.4.0.16811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of HTML files. The issue results from t
nvd
CVE-2019-6753MEDIUMCVSS 5.5≤ 8.3.9.41099≥ 9.0.0, ≤ 9.4.1.168282019-06-03
CVE-2019-6753 [MEDIUM] CWE-190 CVE-2019-6753: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.3.0.10826. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the Stuff method. The issue results fro
nvd
CVE-2019-6758MEDIUMCVSS 5.5≤ 8.3.9.41099≥ 9.0.0, ≤ 9.4.1.168282019-06-03
CVE-2019-6758 [MEDIUM] CWE-416 CVE-2019-6758: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.4.16811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within ConvertToPDF_x86.dll. The issue results from the lack of
nvd
CVE-2019-6772MEDIUMCVSS 5.5≤ 8.3.9.41099≥ 9.0.0, ≤ 9.4.1.168282019-06-03
CVE-2019-6772 [MEDIUM] CWE-416 CVE-2019-6772: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 2019.010.20098. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the removeField method when processing AcroForms. Th
nvd
CVE-2019-6766MEDIUMCVSS 5.5≤ 8.3.9.41099≥ 9.0.0, ≤ 9.4.1.168282019-06-03
CVE-2019-6766 [MEDIUM] CWE-416 CVE-2019-6766: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the removeField method when processing AcroForms. The i
nvd
CVE-2019-6773MEDIUMCVSS 5.5≤ 8.3.9.41099≥ 9.0.0, ≤ 9.4.1.168282019-06-03
CVE-2019-6773 [MEDIUM] CWE-416 CVE-2019-6773: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the richValue property of a Field objec
nvd
CVE-2019-6731HIGHCVSS 8.8≤ 9.3.0.108262019-03-21
CVE-2019-6731 [HIGH] CWE-125 CVE-2019-6731: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the conversion of HTML files to PDF. The issue results from the lack of pr
nvd
CVE-2019-6730HIGHCVSS 8.8≤ 9.3.0.108262019-03-21
CVE-2019-6730 [HIGH] CWE-416 CVE-2019-6730: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the popUpMenu method. The issue results from the lack of validating the existe
nvd
CVE-2019-6727HIGHCVSS 8.8≤ 9.3.0.108262019-03-21
CVE-2019-6727 [HIGH] CWE-416 CVE-2019-6727: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the XFA remerge method. The issue results from the lack of validating the exis
nvd
CVE-2019-6729HIGHCVSS 8.8≤ 9.3.0.108262019-03-21
CVE-2019-6729 [HIGH] CWE-125 CVE-2019-6729: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from the lack of proper validat
nvd
CVE-2019-6735MEDIUMCVSS 6.5≤ 9.3.0.108262019-03-21
CVE-2019-6735 [MEDIUM] CWE-125 CVE-2019-6735: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from the lack of pro
nvd
CVE-2019-6732MEDIUMCVSS 6.5≤ 9.3.0.108262019-03-21
CVE-2019-6732 [MEDIUM] CWE-125 CVE-2019-6732: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the AFParseDateEx method. The issue results fro
nvd
CVE-2019-6728MEDIUMCVSS 6.5≤ 9.3.0.108262019-03-21
CVE-2019-6728 [MEDIUM] CWE-125 CVE-2019-6728: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from the lack of pro
nvd
CVE-2019-6734MEDIUMCVSS 6.5≤ 9.3.0.108262019-03-21
CVE-2019-6734 [MEDIUM] CWE-416 CVE-2019-6734: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the setInterval method. By performing actions i
nvd
CVE-2019-6733MEDIUMCVSS 6.5≤ 9.3.0.108262019-03-21
CVE-2019-6733 [MEDIUM] CWE-125 CVE-2019-6733: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of PDF files. The issue results from the lack of p
nvd
CVE-2018-3956HIGHCVSS 7.1≤ 9.3.0.108262019-01-30
CVE-2018-3956 [HIGH] CWE-125 CVE-2018-3956: An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attrib An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Software's PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger an out-of-bounds read, which can disclose sensitive memory content and aid in exploitation when coupled with another vulnerability. An attacker needs to t
nvd