cbcvebase.

Foxitsoftware Phantompdf vulnerabilities

549 known vulnerabilities affecting foxitsoftware/phantompdf.

Total CVEs
549
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL26HIGH438MEDIUM68LOW17

Vulnerabilities

Page 14 of 28
CVE-2018-10483P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-10483 [HIGH] CWE-787 CVE-2018-10483: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Clod Progressive Mesh objects. The issue resu
nvd
CVE-2018-10477P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-10477 [HIGH] CWE-787 CVE-2018-10477: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Chain Index objects. The issue results from t
nvd
CVE-2018-10474P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-10474 [HIGH] CWE-787 CVE-2018-10474: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Shading objects. The issue results from the l
nvd
CVE-2018-10489P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-17
CVE-2018-10489 [HIGH] CWE-787 CVE-2018-10489: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Clod Progressive Mesh Declaration structures.
nvd
CVE-2018-10303P3HIGHCVSS 8.8fixed in 9.12018-04-23
CVE-2018-10303 [HIGH] CWE-416 CVE-2018-10303: A use-after-free in Foxit Reader before 9.1 and PhantomPDF before 9.1 allows remote attackers to exe A use-after-free in Foxit Reader before 9.1 and PhantomPDF before 9.1 allows remote attackers to execute arbitrary code, aka iDefense ID V-y0nqfutlf3.
nvd
CVE-2018-17686P3MEDIUMCVSS 6.5≤ 9.2.0.92972019-01-24
CVE-2018-17686 [MEDIUM] CWE-125 CVE-2018-17686: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of BMP images. The issue results from t
nvd
CVE-2020-17416P3HIGHCVSS 7.8≤ 10.0.1.358112020-10-13
CVE-2020-17416 [HIGH] CWE-787 CVE-2020-17416: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.0.0.35798. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPEG2000 images. The issue results from the lack
nvd
CVE-2015-3632P4MEDIUMCVSS 4.3PoC≤ 7.1.3.3202015-05-01
CVE-2015-3632 [MEDIUM] CWE-119 CVE-2015-3632: Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denia Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted GIF in a PDF file.
nvd
CVE-2019-13315P3HIGHCVSS 7.8≤ 8.3.10.42705≥ 9.0, ≤ 9.5.0.207232019-10-04
CVE-2019-13315 [HIGH] CWE-416 CVE-2019-13315: This vulnerability allows remote atackers to execute arbitrary code on affected installations of Fox This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the removeField method. The issue results from the lack of validat
nvd
CVE-2019-13316P3HIGHCVSS 7.8≤ 8.3.10.42705≥ 9.0, ≤ 9.5.0.207232019-10-04
CVE-2019-13316 [HIGH] CWE-416 CVE-2019-13316: This vulnerability allows remote atackers to execute arbitrary code on affected installations of Fox This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Calculate actions. The issue results from the
nvd
CVE-2019-13317P3HIGHCVSS 7.8≤ 8.3.10.42705≥ 9.0, ≤ 9.5.0.207232019-10-04
CVE-2019-13317 [HIGH] CWE-416 CVE-2019-13317: This vulnerability allows remote atackers to execute arbitrary code on affected installations of Fox This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Calculate actions. The issue results from the
nvd
CVE-2020-26535P3CRITICALCVSS 9.8fixed in 10.12020-10-02
CVE-2020-26535 [CRITICAL] CWE-787 CVE-2020-26535: An issue was discovered in Foxit Reader and PhantomPDF before 10.1. If TslAlloc attempts to allocate An issue was discovered in Foxit Reader and PhantomPDF before 10.1. If TslAlloc attempts to allocate thread local storage but obtains an unacceptable index value, V8 throws an exception that leads to a write access violation (and read access violation).
nvd
CVE-2021-31476P3HIGHCVSS 7.8≤ 9.7.5.29616≥ 10.0.0.0, ≤ 10.1.3.375982021-06-16
CVE-2021-31476 [HIGH] CWE-843 CVE-2021-31476: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.3.37598. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of XFA templates. The issue results from the la
nvd
CVE-2020-10906P3HIGHCVSS 7.8≤ 9.7.1.295112020-04-22
CVE-2020-10906 [HIGH] CWE-416 CVE-2020-10906: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the resetForm method. The issue results from the lack of validati
nvd
CVE-2020-10907P3HIGHCVSS 7.8≤ 9.7.1.295112020-04-22
CVE-2020-10907 [HIGH] CWE-416 CVE-2020-10907: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of widgets in XFA forms. The issue results from the
nvd
CVE-2020-10900P3HIGHCVSS 7.8≤ 9.7.1.295112020-04-22
CVE-2020-10900 [HIGH] CWE-416 CVE-2020-10900: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of AcroForms. The issue results from the lack of v
nvd
CVE-2020-10899P3HIGHCVSS 7.8≤ 9.7.1.295112020-04-22
CVE-2020-10899 [HIGH] CWE-416 CVE-2020-10899: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XFA templates. The issue results from the lack
nvd
CVE-2019-13319P3HIGHCVSS 7.8≤ 8.3.10.42705≥ 9.0, ≤ 9.5.0.207232019-10-04
CVE-2019-13319 [HIGH] CWE-416 CVE-2019-13319: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XFA forms. The issue results from the lack of v
nvd
CVE-2019-13320P3HIGHCVSS 7.8≤ 8.3.10.42705≥ 9.0, ≤ 9.5.0.207232019-10-04
CVE-2019-13320 [HIGH] CWE-416 CVE-2019-13320: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of AcroForms. The issue results from the lack of v
nvd
CVE-2020-26534P3CRITICALCVSS 9.8fixed in 10.12020-10-02
CVE-2020-26534 [CRITICAL] CWE-416 CVE-2020-26534: An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Field::ClearItems and Field::DeleteOptions, during AcroForm JavaScript execution.
nvd