Foxitsoftware Phantompdf vulnerabilities
549 known vulnerabilities affecting foxitsoftware/phantompdf.
Total CVEs
549
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL26HIGH438MEDIUM68LOW17
Vulnerabilities
Page 20 of 28
CVE-2018-20314P3HIGHCVSS 8.1fixed in 8.3.10≥ 9.0, < 9.52021-01-07
CVE-2018-20314 [HIGH] CWE-125 CVE-2018-20314: Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCheckLicence ra
Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCheckLicence race condition that can cause a stack-based buffer overflow or an out-of-bounds read.
nvd
CVE-2018-20313P3HIGHCVSS 8.1fixed in 8.3.10≥ 9.0, < 9.52021-01-07
CVE-2018-20313 [HIGH] CWE-125 CVE-2018-20313: Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyPreviewAction r
Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyPreviewAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read.
nvd
CVE-2018-20311P3HIGHCVSS 8.1fixed in 8.3.10≥ 9.0, < 9.52021-01-07
CVE-2018-20311 [HIGH] CWE-125 CVE-2018-20311: Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCPDFAction race
Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCPDFAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read.
nvd
CVE-2018-20309P3HIGHCVSS 8.1fixed in 8.3.10≥ 9.0, < 9.52021-01-07
CVE-2018-20309 [HIGH] CWE-125 CVE-2018-20309: Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyGetAppEdition r
Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyGetAppEdition race condition that can cause a stack-based buffer overflow or an out-of-bounds read.
nvd
CVE-2018-20315P3HIGHCVSS 8.1fixed in 8.3.10≥ 9.0, < 9.52021-01-07
CVE-2018-20315 [HIGH] CWE-362 CVE-2018-20315: Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a race condition that
Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a race condition that can cause a stack-based buffer overflow or an out-of-bounds read.
nvd
CVE-2016-8876P3HIGHCVSS 7.5≤ 8.0.52016-10-31
CVE-2016-8876 [HIGH] CWE-125 CVE-2016-8876: Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gfla
Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF image embedded in the XFA stream in a PDF document, aka "Read Access Violation starting at FoxitReader."
nvd
CVE-2018-3966P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-03
CVE-2018-3966 [HIGH] CWE-416 CVE-2018-3966: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxi
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerabi
nvd
CVE-2018-3967P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-03
CVE-2018-3967 [HIGH] CWE-416 CVE-2018-3967: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxi
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerabi
nvd
CVE-2021-33793P3CRITICALCVSS 9.8fixed in 10.1.42021-08-11
CVE-2021-33793 [CRITICAL] CWE-787 CVE-2021-33793: Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write because the Cros
Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write because the Cross-Reference table is mishandled during Office document conversion.
nvd
CVE-2018-3965P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-03
CVE-2018-3965 [HIGH] CWE-416 CVE-2018-3965: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxi
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerabi
nvd
CVE-2018-3940P3HIGHCVSS 8.8≤ 9.2.0.92972018-10-08
CVE-2018-3940 [HIGH] CWE-416 CVE-2018-3940: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused. An attacker needs to trick the user to open the malicious file to trigger.
nvd
CVE-2018-20312P3HIGHCVSS 8.1fixed in 8.3.10≥ 9.0, < 9.52021-01-07
CVE-2018-20312 [HIGH] CVE-2018-20312: Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race c
Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read, a different issue than CVE-2018-20310 because of a different opcode.
nvd
CVE-2018-20316P3HIGHCVSS 8.1fixed in 8.3.10≥ 9.0, < 9.52021-01-07
CVE-2018-20316 [HIGH] CVE-2018-20316: Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race c
Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read, a different issue than CVE-2018-20310 because of a different opcode.
nvd
CVE-2019-14209P3CRITICALCVSS 9.8fixed in 8.3.102019-07-21
CVE-2019-14209 [CRITICAL] CWE-787 CVE-2019-14209: An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to Heap
An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to Heap Corruption due to data desynchrony when adding AcroForm.
nvd
CVE-2019-20830P3CRITICALCVSS 9.8fixed in 9.62020-06-04
CVE-2019-20830 [CRITICAL] CWE-787 CVE-2019-20830: An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has an out-of-bounds write whe
An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has an out-of-bounds write when Internet Explorer is used.
nvd
CVE-2016-4063P3HIGHCVSS 7.8≤ 7.3.0.1182016-04-22
CVE-2016-4063 [HIGH] CVE-2016-4063: Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote at
Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via an object with a revision number of -1 in a PDF document.
nvd
CVE-2021-33794P3CRITICALCVSS 9.1fixed in 10.1.42021-08-11
CVE-2021-33794 [CRITICAL] CVE-2021-33794: Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 allow information disclosure or an applicati
Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 allow information disclosure or an application crash after mishandling the Tab key during XFA form interaction.
nvd
CVE-2020-13805P3CRITICALCVSS 9.8fixed in 9.7.22020-06-04
CVE-2020-13805 [CRITICAL] CWE-307 CVE-2020-13805: An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has brute-force attack misha
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has brute-force attack mishandling because the CAS service lacks a limit on login failures.
nvd
CVE-2020-26537P3CRITICALCVSS 9.8fixed in 10.12020-10-02
CVE-2020-26537 [CRITICAL] CWE-787 CVE-2020-26537: An issue was discovered in Foxit Reader and PhantomPDF before 10.1. In a certain Shading calculation
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. In a certain Shading calculation, the number of outputs is unequal to the number of color components in a color space. This causes an out-of-bounds write.
nvd
CVE-2021-38568P3CRITICALCVSS 9.8fixed in 10.1.42021-08-11
CVE-2021-38568 [CRITICAL] CWE-787 CVE-2021-38568: An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows memory corruption du
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows memory corruption during conversion of a PDF document to a different document format.
nvd