Foxitsoftware Phantompdf vulnerabilities
549 known vulnerabilities affecting foxitsoftware/phantompdf.
Total CVEs
549
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL26HIGH438MEDIUM68LOW17
Vulnerabilities
Page 21 of 28
CVE-2016-6169P3HIGHCVSS 7.8≤ 7.3.4.3112018-02-07
CVE-2016-6169 [HIGH] CWE-119 CVE-2016-6169: Heap-based buffer overflow in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows re
Heap-based buffer overflow in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to cause a denial of service (memory corruption and application crash) or potentially execute arbitrary code via the Bezier data in a crafted PDF file.
nvd
CVE-2018-16293P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-08
CVE-2018-16293 [HIGH] CVE-2018-16293: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16292, CVE-2018-16294, CVE-2018-16295, CVE-2018-16296, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resul
nvd
CVE-2018-16294P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-08
CVE-2018-16294 [HIGH] CVE-2018-16294: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16292, CVE-2018-16293, CVE-2018-16295, CVE-2018-16296, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resul
nvd
CVE-2018-16297P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-08
CVE-2018-16297 [HIGH] CVE-2018-16297: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16292, CVE-2018-16293, CVE-2018-16294, CVE-2018-16295, and CVE-2018-16296. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resul
nvd
CVE-2018-16292P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-08
CVE-2018-16292 [HIGH] CVE-2018-16292: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16293, CVE-2018-16294, CVE-2018-16295, CVE-2018-16296, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resul
nvd
CVE-2018-16296P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-08
CVE-2018-16296 [HIGH] CVE-2018-16296: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16292, CVE-2018-16293, CVE-2018-16294, CVE-2018-16295, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resul
nvd
CVE-2018-16291P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-08
CVE-2018-16291 [HIGH] CWE-416 CVE-2018-16291: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16292, CVE-2018-16293, CVE-2018-16294, CVE-2018-16295, CVE-2018-16296, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reuse
nvd
CVE-2018-16295P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-08
CVE-2018-16295 [HIGH] CVE-2018-16295: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16292, CVE-2018-16293, CVE-2018-16294, CVE-2018-16296, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resul
nvd
CVE-2021-33792P3HIGHCVSS 7.8fixed in 10.1.42021-07-09
CVE-2021-33792 [HIGH] CWE-787 CVE-2021-33792: Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write via a crafted /S
Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write via a crafted /Size key in the Trailer dictionary.
nvd
CVE-2020-13814P3CRITICALCVSS 9.8fixed in 9.7.12020-06-04
CVE-2020-13814 [CRITICAL] CWE-416 CVE-2020-13814: An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It has a use-after-free via a d
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It has a use-after-free via a document that lacks a dictionary.
nvd
CVE-2017-8455P3HIGHCVSS 7.8≤ 8.2.0.21922017-05-03
CVE-2017-8455 [HIGH] CWE-125 CVE-2017-8455: Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote
Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document.
nvd
CVE-2020-35931P3HIGHCVSS 7.8fixed in 9.7.5≥ 10.0.0, < 10.1.1+1 more2020-12-31
CVE-2020-35931 [HIGH] CWE-754 CVE-2020-35931: An issue was discovered in Foxit Reader before 10.1.1 (and before 4.1.1 on macOS) and PhantomPDF bef
An issue was discovered in Foxit Reader before 10.1.1 (and before 4.1.1 on macOS) and PhantomPDF before 9.7.5 and 10.x before 10.1.1 (and before 4.1.1 on macOS). An attacker can spoof a certified PDF document via an Evil Annotation Attack because the products fail to consider a null value for a Subtype entry of the Annotation dictionary, in an increme
nvd
CVE-2018-17781P3HIGHCVSS 7.5≤ 9.2.0.92972018-09-29
CVE-2018-17781 [HIGH] CWE-200 CVE-2018-17781: Foxit PhantomPDF and Reader before 9.3 allow remote attackers to trigger Uninitialized Object Inform
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to trigger Uninitialized Object Information Disclosure because creation of ArrayBuffer and DataView objects is mishandled.
nvd
CVE-2018-3957P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-02
CVE-2018-3957 [HIGH] CWE-416 CVE-2018-3957: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Keywords property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled,
nvd
CVE-2018-3958P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-02
CVE-2018-3958 [HIGH] CWE-416 CVE-2018-3958: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Subject property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled,
nvd
CVE-2018-3959P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-02
CVE-2018-3959 [HIGH] CWE-416 CVE-2018-3959: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Author property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, v
nvd
CVE-2018-3961P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-02
CVE-2018-3961 [HIGH] CWE-416 CVE-2018-3961: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Creator property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled,
nvd
CVE-2018-3960P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-02
CVE-2018-3960 [HIGH] CWE-416 CVE-2018-3960: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Producer property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled,
nvd
CVE-2019-20836P3HIGHCVSS 7.5fixed in 9.52020-06-04
CVE-2019-20836 [HIGH] CWE-200 CVE-2019-20836: An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It has mishandling of cloud crede
An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It has mishandling of cloud credentials, as demonstrated by Google Drive.
nvd
CVE-2019-20833P3HIGHCVSS 7.5fixed in 8.3.102020-06-04
CVE-2019-20833 [HIGH] CWE-287 CVE-2019-20833: An issue was discovered in Foxit PhantomPDF before 8.3.10. It has mishandling of cloud credentials,
An issue was discovered in Foxit PhantomPDF before 8.3.10. It has mishandling of cloud credentials, as demonstrated by Google Drive.
nvd