cbcvebase.

Foxitsoftware Phantompdf vulnerabilities

549 known vulnerabilities affecting foxitsoftware/phantompdf.

Total CVEs
549
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL26HIGH438MEDIUM68LOW17

Vulnerabilities

Page 13 of 28
CVE-2018-14249P3HIGHCVSS 8.8≤ 9.1.0.50962018-07-31
CVE-2018-14249 [HIGH] CWE-843 CVE-2018-14249: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the exportDataObject method. By performing actions in JavaScript,
nvd
CVE-2018-14277P3HIGHCVSS 8.8≤ 9.1.0.50962018-07-31
CVE-2018-14277 [HIGH] CWE-843 CVE-2018-14277: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the mailDoc method. By performing actions in JavaScript, an attac
nvd
CVE-2018-14273P3HIGHCVSS 8.8≤ 9.1.0.50962018-07-31
CVE-2018-14273 [HIGH] CWE-843 CVE-2018-14273: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the removeTemplate method. By performing actions in JavaScript, a
nvd
CVE-2018-14276P3HIGHCVSS 8.8≤ 9.1.0.50962018-07-31
CVE-2018-14276 [HIGH] CWE-843 CVE-2018-14276: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the submitForm method. By performing actions in JavaScript, an at
nvd
CVE-2018-14257P3HIGHCVSS 8.8≤ 9.1.0.50962018-07-31
CVE-2018-14257 [HIGH] CWE-843 CVE-2018-14257: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the getPageBox method. By performing actions in JavaScript, an at
nvd
CVE-2018-14275P3HIGHCVSS 8.8≤ 9.1.0.50962018-07-31
CVE-2018-14275 [HIGH] CWE-843 CVE-2018-14275: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the spawnPageFromTemplate method. By performing actions in JavaSc
nvd
CVE-2018-10495P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-10495 [HIGH] CWE-843 CVE-2018-10495: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF documents. The issue results from the lack of
nvd
CVE-2018-10490P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-10490 [HIGH] CWE-119 CVE-2018-10490: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPEG images embedded inside U3D files. The issue
nvd
CVE-2018-9936P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-9936 [HIGH] CWE-704 CVE-2018-9936: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of field elements. The issue results from the lack of
nvd
CVE-2020-10890P3HIGHCVSS 8.8≤ 9.7.1.295112020-04-22
CVE-2020-10890 [HIGH] CWE-352 CVE-2020-10890: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the communication API. The issue lies in the handling of the
nvd
CVE-2020-10892P3HIGHCVSS 8.8≤ 9.7.1.295112020-04-22
CVE-2020-10892 [HIGH] CWE-352 CVE-2020-10892: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the communication API. The issue lies in the handling of the
nvd
CVE-2019-5031P3HIGHCVSS 8.8≤ 9.4.1.168282019-10-02
CVE-2019-5031 [HIGH] CWE-703 CVE-2019-5031: An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's F An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.4.1.16828. A specially crafted PDF document can trigger an out-of-memory condition which isn't handled properly, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger th
nvd
CVE-2018-21244P3CRITICALCVSS 9.8fixed in 8.3.62020-06-04
CVE-2018-21244 [CRITICAL] CWE-434 CVE-2018-21244: An issue was discovered in Foxit PhantomPDF before 8.3.6. It allows arbitrary application execution An issue was discovered in Foxit PhantomPDF before 8.3.6. It allows arbitrary application execution via an embedded executable file in a PDF portfolio, aka FG-VD-18-029.
nvd
CVE-2020-8857P3HIGHCVSS 7.8≤ 9.7.0.294552020-02-14
CVE-2020-8857 [HIGH] CWE-416 CVE-2020-8857: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of form Annotation objects within AcroForms. The issue
nvd
CVE-2020-8855P3HIGHCVSS 7.8≤ 9.7.0.294552020-02-14
CVE-2020-8855 [HIGH] CWE-416 CVE-2020-8855: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.2947. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the fxhtml2pdf.exe module. The issue results from the lack of va
nvd
CVE-2021-38574P3CRITICALCVSS 9.8fixed in 10.1.42021-08-11
CVE-2021-38574 [CRITICAL] CWE-89 CVE-2021-38574: An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via cr An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.
nvd
CVE-2018-11622P3HIGHCVSS 8.8≤ 9.1.0.50962018-07-31
CVE-2018-11622 [HIGH] CWE-787 CVE-2018-11622: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within ConvertToPDF_x86.dll. The issue results from the lack of proper v
nvd
CVE-2018-9982P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-9982 [HIGH] CWE-787 CVE-2018-9982: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of the Texture Width in U3D files. The issue results f
nvd
CVE-2018-10473P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-10473 [HIGH] CWE-787 CVE-2018-10473: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D CLOD Base Mesh Continuation structures. The i
nvd
CVE-2018-10491P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-10491 [HIGH] CWE-787 CVE-2018-10491: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Bone Weight Modifier structures. The issue re
nvd
Foxitsoftware Phantompdf vulnerabilities | cvebase