cbcvebase.

Foxitsoftware Phantompdf vulnerabilities

549 known vulnerabilities affecting foxitsoftware/phantompdf.

Total CVEs
549
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL26HIGH438MEDIUM68LOW17

Vulnerabilities

Page 22 of 28
CVE-2019-20834P3HIGHCVSS 7.5fixed in 8.3.102020-06-04
CVE-2019-20834 [HIGH] CWE-347 CVE-2019-20834: An issue was discovered in Foxit PhantomPDF before 8.3.10. It allows signature validation bypass via An issue was discovered in Foxit PhantomPDF before 8.3.10. It allows signature validation bypass via a modified file or a file with non-standard signatures.
nvd
CVE-2019-20825P3CRITICALCVSS 9.8fixed in 8.3.112020-06-04
CVE-2019-20825 [CRITICAL] CWE-787 CVE-2019-20825: An issue was discovered in Foxit PhantomPDF before 8.3.11. It has an out-of-bounds write when Intern An issue was discovered in Foxit PhantomPDF before 8.3.11. It has an out-of-bounds write when Internet Explorer is used.
nvd
CVE-2020-26540P3HIGHCVSS 7.5fixed in 4.12020-10-02
CVE-2020-26540 [HIGH] CWE-347 CVE-2020-26540: An issue was discovered in Foxit Reader and PhantomPDF before 4.1 on macOS. Because the Hardened Run An issue was discovered in Foxit Reader and PhantomPDF before 4.1 on macOS. Because the Hardened Runtime protection mechanism is not applied to code signing, code injection (or an information leak) can occur.
nvd
CVE-2017-5556P3HIGHCVSS 8.1v8.1.1.11152017-01-23
CVE-2017-5556 [HIGH] CWE-125 CVE-2017-5556: The ConvertToPDF plugin in Foxit Reader before 8.2 and PhantomPDF before 8.2 on Windows, when the gf The ConvertToPDF plugin in Foxit Reader before 8.2 and PhantomPDF before 8.2 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG image. The vulnerability could lead to information disclosure; an attacker can leverage this in conjunction with other
nvd
CVE-2019-6728P3MEDIUMCVSS 6.5≤ 9.3.0.108262019-03-21
CVE-2019-6728 [MEDIUM] CWE-125 CVE-2019-6728: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from the lack of pro
nvd
CVE-2020-13806P3HIGHCVSS 7.5fixed in 9.7.22020-06-04
CVE-2020-13806 [HIGH] CWE-416 CVE-2020-13806: An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has a use-after-free because An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has a use-after-free because of JavaScript execution after a deletion or close operation.
nvd
CVE-2015-8580P3MEDIUMCVSS 6.8≤ 7.2.0.7222015-12-16
CVE-2015-8580 [MEDIUM] CVE-2015-8580: Multiple use-after-free vulnerabilities in the (1) Print method and (2) App object handling in Foxit Multiple use-after-free vulnerabilities in the (1) Print method and (2) App object handling in Foxit Reader before 7.2.2 and Foxit PhantomPDF before 7.2.2 allow remote attackers to execute arbitrary code via a crafted PDF document.
nvd
CVE-2019-6735P3MEDIUMCVSS 6.5≤ 9.3.0.108262019-03-21
CVE-2019-6735 [MEDIUM] CWE-125 CVE-2019-6735: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from the lack of pro
nvd
CVE-2019-14211P3HIGHCVSS 7.5fixed in 8.3.112019-07-21
CVE-2019-14211 [HIGH] CWE-20 CVE-2019-14211: An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash due to the la An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash due to the lack of proper validation of the existence of an object prior to performing operations on that object when executing JavaScript.
nvd
CVE-2020-13808P3HIGHCVSS 7.5fixed in 9.7.22020-06-04
CVE-2020-13808 [HIGH] CWE-835 CVE-2020-13808: An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption via crafted cross-reference stream data.
nvd
CVE-2019-20815P3HIGHCVSS 7.5fixed in 8.3.122020-06-04
CVE-2019-20815 [HIGH] CWE-674 CVE-2019-20815: An issue was discovered in Foxit PhantomPDF before 8.3.12. It allows stack consumption via nested fu An issue was discovered in Foxit PhantomPDF before 8.3.12. It allows stack consumption via nested function calls for XML parsing.
nvd
CVE-2019-20823P3HIGHCVSS 7.5fixed in 8.3.112020-06-04
CVE-2019-20823 [HIGH] CWE-120 CVE-2019-20823: An issue was discovered in Foxit PhantomPDF before 8.3.11. It has a buffer overflow because a loopin An issue was discovered in Foxit PhantomPDF before 8.3.11. It has a buffer overflow because a looping correction does not occur after JavaScript updates Field APs.
nvd
CVE-2020-13810P3HIGHCVSS 7.5fixed in 9.7.22020-06-04
CVE-2020-13810 [HIGH] CWE-347 CVE-2020-13810: An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows signature validation An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows signature validation bypass via a modified file or a file with non-standard signatures.
nvd
CVE-2019-20837P3HIGHCVSS 7.5fixed in 9.52020-06-04
CVE-2019-20837 [HIGH] CWE-347 CVE-2019-20837: An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It allows signature validation by An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It allows signature validation bypass via a modified file or a file with non-standard signatures.
nvd
CVE-2021-38569P3HIGHCVSS 7.5fixed in 10.1.42021-08-11
CVE-2021-38569 [HIGH] CWE-674 CVE-2021-38569: An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows stack consumption vi An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows stack consumption via recursive function calls during the handling of XFA forms or link objects.
nvd
CVE-2020-13803P3HIGHCVSS 7.5fixed in 4.02020-06-04
CVE-2020-13803 [HIGH] CWE-347 CVE-2020-13803: An issue was discovered in Foxit PhantomPDF Mac and Foxit Reader for Mac before 4.0. It allows signa An issue was discovered in Foxit PhantomPDF Mac and Foxit Reader for Mac before 4.0. It allows signature validation bypass via a modified file or a file with non-standard signatures.
nvd
CVE-2019-14212P3HIGHCVSS 7.5fixed in 8.3.112019-07-21
CVE-2019-14212 [HIGH] CWE-476 CVE-2019-14212: An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling certain XFA JavaScript due to the use of, or access to, a NULL pointer without proper validation on the object.
nvd
CVE-2019-14207P3HIGHCVSS 7.5fixed in 8.3.112019-07-21
CVE-2019-14207 [HIGH] CWE-835 CVE-2019-14207: An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling the clone function due to an endless loop resulting from confusing relationships between a child and parent object (caused by an append error).
nvd
CVE-2018-3962P3HIGHCVSS 7.3≤ 9.2.0.92972018-10-02
CVE-2018-3962 [HIGH] CWE-416 CVE-2018-3962: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the CreationDate property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enab
nvd
CVE-2019-6733P3MEDIUMCVSS 6.5≤ 9.3.0.108262019-03-21
CVE-2019-6733 [MEDIUM] CWE-125 CVE-2019-6733: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of PDF files. The issue results from the lack of p
nvd
Foxitsoftware Phantompdf vulnerabilities | cvebase