Foxitsoftware Phantompdf vulnerabilities

549 known vulnerabilities affecting foxitsoftware/phantompdf.

Total CVEs
549
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL26HIGH438MEDIUM68LOW17

Vulnerabilities

Page 17 of 28
CVE-2018-3997HIGHCVSS 8.8≤ 9.2.0.92972018-10-08
CVE-2018-3997 [HIGH] CWE-416 CVE-2018-3997: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxi An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.2.0.9297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerab
nvd
CVE-2018-16291HIGHCVSS 7.8≤ 9.2.0.92972018-10-08
CVE-2018-16291 [HIGH] CWE-416 CVE-2018-16291: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9 An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16292, CVE-2018-16293, CVE-2018-16294, CVE-2018-16295, CVE-2018-16296, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reuse
nvd
CVE-2018-3942HIGHCVSS 8.8≤ 9.2.0.92972018-10-08
CVE-2018-3942 [HIGH] CWE-416 CVE-2018-3942: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability.
nvd
CVE-2018-3992HIGHCVSS 8.8≤ 9.2.0.92972018-10-08
CVE-2018-3992 [HIGH] CWE-416 CVE-2018-3992: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxi An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.2.0.9297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerab
nvd
CVE-2018-16295HIGHCVSS 7.8≤ 9.2.0.92972018-10-08
CVE-2018-16295 [HIGH] CVE-2018-16295: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9 An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16292, CVE-2018-16293, CVE-2018-16294, CVE-2018-16296, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resul
nvd
CVE-2018-3996HIGHCVSS 8.8≤ 9.2.0.92972018-10-08
CVE-2018-3996 [HIGH] CWE-416 CVE-2018-3996: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.2.0.9297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability.
nvd
CVE-2018-3946HIGHCVSS 8.8≤ 9.2.0.92972018-10-03
CVE-2018-3946 [HIGH] CWE-416 CVE-2018-3946: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. I
nvd
CVE-2018-3965HIGHCVSS 7.8≤ 9.2.0.92972018-10-03
CVE-2018-3965 [HIGH] CWE-416 CVE-2018-3965: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxi An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerabi
nvd
CVE-2018-3966HIGHCVSS 7.8≤ 9.2.0.92972018-10-03
CVE-2018-3966 [HIGH] CWE-416 CVE-2018-3966: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxi An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerabi
nvd
CVE-2018-3964HIGHCVSS 7.8≤ 9.2.0.92972018-10-03
CVE-2018-3964 [HIGH] CWE-416 CVE-2018-3964: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxi An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerabi
nvd
CVE-2018-3995HIGHCVSS 8.8≤ 9.2.0.92972018-10-03
CVE-2018-3995 [HIGH] CWE-416 CVE-2018-3995: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.2.0.9297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability.
nvd
CVE-2018-3994HIGHCVSS 8.8≤ 9.2.0.92972018-10-03
CVE-2018-3994 [HIGH] CWE-416 CVE-2018-3994: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxi An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.2.0.9297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerabi
nvd
CVE-2018-3967HIGHCVSS 7.8≤ 9.2.0.92972018-10-03
CVE-2018-3967 [HIGH] CWE-416 CVE-2018-3967: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxi An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerabi
nvd
CVE-2018-3993HIGHCVSS 8.8≤ 9.2.0.92972018-10-03
CVE-2018-3993 [HIGH] CWE-416 CVE-2018-3993: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxi An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.2.0.9297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerabi
nvd
CVE-2018-3957HIGHCVSS 7.8≤ 9.2.0.92972018-10-02
CVE-2018-3957 [HIGH] CWE-416 CVE-2018-3957: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Keywords property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled,
nvd
CVE-2018-3959HIGHCVSS 7.8≤ 9.2.0.92972018-10-02
CVE-2018-3959 [HIGH] CWE-416 CVE-2018-3959: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Author property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, v
nvd
CVE-2018-3943HIGHCVSS 8.8≤ 9.2.0.92972018-10-02
CVE-2018-3943 [HIGH] CWE-416 CVE-2018-3943: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability.
nvd
CVE-2018-3961HIGHCVSS 7.8≤ 9.2.0.92972018-10-02
CVE-2018-3961 [HIGH] CWE-416 CVE-2018-3961: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Creator property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled,
nvd
CVE-2018-3962HIGHCVSS 7.3≤ 9.2.0.92972018-10-02
CVE-2018-3962 [HIGH] CWE-416 CVE-2018-3962: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the CreationDate property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enab
nvd
CVE-2018-3960HIGHCVSS 7.8≤ 9.2.0.92972018-10-02
CVE-2018-3960 [HIGH] CWE-416 CVE-2018-3960: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Producer property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled,
nvd