cbcvebase.

Foxitsoftware Phantompdf vulnerabilities

549 known vulnerabilities affecting foxitsoftware/phantompdf.

Total CVEs
549
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL26HIGH438MEDIUM68LOW17

Vulnerabilities

Page 23 of 28
CVE-2019-6734P3MEDIUMCVSS 6.5≤ 9.3.0.108262019-03-21
CVE-2019-6734 [MEDIUM] CWE-416 CVE-2019-6734: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the setInterval method. By performing actions i
nvd
CVE-2019-6732P3MEDIUMCVSS 6.5≤ 9.3.0.108262019-03-21
CVE-2019-6732 [MEDIUM] CWE-125 CVE-2019-6732: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the AFParseDateEx method. The issue results fro
nvd
CVE-2018-17699P3MEDIUMCVSS 6.5≤ 9.2.0.92972019-01-24
CVE-2018-17699 [MEDIUM] CWE-125 CVE-2018-17699: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from th
nvd
CVE-2019-20824P3HIGHCVSS 7.5fixed in 8.3.112020-06-04
CVE-2019-20824 [HIGH] CWE-476 CVE-2019-20824: An issue was discovered in Foxit PhantomPDF before 8.3.11. It has a NULL pointer dereference via FXS An issue was discovered in Foxit PhantomPDF before 8.3.11. It has a NULL pointer dereference via FXSYS_wcslen in an Epub file.
nvd
CVE-2019-20816P3HIGHCVSS 7.5fixed in 8.3.122020-06-04
CVE-2019-20816 [HIGH] CWE-476 CVE-2019-20816: An issue was discovered in Foxit PhantomPDF before 8.3.12. It has a NULL pointer dereference during An issue was discovered in Foxit PhantomPDF before 8.3.12. It has a NULL pointer dereference during the parsing of file data.
nvd
CVE-2019-20813P3HIGHCVSS 7.5fixed in 8.3.122020-06-04
CVE-2019-20813 [HIGH] CWE-476 CVE-2019-20813: An issue was discovered in Foxit PhantomPDF before 8.3.12. It has a NULL pointer dereference. An issue was discovered in Foxit PhantomPDF before 8.3.12. It has a NULL pointer dereference.
nvd
CVE-2020-13815P3HIGHCVSS 7.5fixed in 9.7.12020-06-04
CVE-2020-13815 [HIGH] CWE-400 CVE-2020-13815: An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It allows stack consumption via An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It allows stack consumption via a loop of an indirect object reference.
nvd
CVE-2019-20814P3HIGHCVSS 7.5fixed in 8.3.122020-06-04
CVE-2019-20814 [HIGH] CWE-770 CVE-2019-20814: An issue was discovered in Foxit PhantomPDF before 8.3.12. It allows memory consumption because data An issue was discovered in Foxit PhantomPDF before 8.3.12. It allows memory consumption because data is created for each page of an application level.
nvd
CVE-2019-20828P3HIGHCVSS 7.5fixed in 9.62020-06-04
CVE-2019-20828 [HIGH] CWE-120 CVE-2019-20828: An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has a buffer overflow because An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has a buffer overflow because a looping correction does not occur after JavaScript updates Field APs.
nvd
CVE-2020-26538P3HIGHCVSS 7.8fixed in 10.12020-10-02
CVE-2020-26538 [HIGH] CWE-427 CVE-2020-26538: An issue was discovered in Foxit Reader and PhantomPDF before 10.1. It allows attackers to execute a An issue was discovered in Foxit Reader and PhantomPDF before 10.1. It allows attackers to execute arbitrary code via a Trojan horse taskkill.exe in the current working directory.
nvd
CVE-2018-9972P3MEDIUMCVSS 6.5≤ 9.0.1.10492018-05-17
CVE-2018-9972 [MEDIUM] CWE-125 CVE-2018-9972: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within ConvertToPDF_x86.dll. The issue results from the lack of
nvd
CVE-2018-9973P3MEDIUMCVSS 6.5≤ 9.0.1.10492018-05-17
CVE-2018-9973 [MEDIUM] CWE-125 CVE-2018-9973: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ePub files. The issue results from the la
nvd
CVE-2018-11621P3MEDIUMCVSS 6.5≤ 9.1.0.50962018-07-31
CVE-2018-11621 [MEDIUM] CWE-125 CVE-2018-11621: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within ConvertToPDF_x86.dll. The issue results from the lack
nvd
CVE-2018-11620P3MEDIUMCVSS 6.5≤ 9.1.0.50962018-07-31
CVE-2018-11620 [MEDIUM] CWE-125 CVE-2018-11620: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within ConvertToPDF_x86.dll. The issue results from the lack
nvd
CVE-2019-14213P4HIGHCVSS 7.5fixed in 8.3.112019-07-21
CVE-2019-14213 [HIGH] CVE-2019-14213: An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash due to the re An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash due to the repeated release of the signature dictionary during CSG_SignatureF and CPDF_Document destruction.
nvd
CVE-2018-9950P4MEDIUMCVSS 6.5≤ 9.0.1.10492018-05-17
CVE-2018-9950 [MEDIUM] CWE-125 CVE-2018-9950: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF documents. The issue results from th
nvd
CVE-2019-20820P4HIGHCVSS 7.5fixed in 9.72020-06-04
CVE-2019-20820 [HIGH] CWE-476 CVE-2019-20820: An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It has a NULL pointer dereference An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It has a NULL pointer dereference during the parsing of file data.
nvd
CVE-2018-21241P4HIGHCVSS 7.8fixed in 8.3.62020-06-04
CVE-2018-21241 [HIGH] CWE-426 CVE-2018-21241: An issue was discovered in Foxit PhantomPDF before 8.3.6. It has an untrusted search path that allow An issue was discovered in Foxit PhantomPDF before 8.3.6. It has an untrusted search path that allows a DLL to execute remote code.
nvd
CVE-2019-20819P4HIGHCVSS 7.5fixed in 9.72020-06-04
CVE-2019-20819 [HIGH] CWE-674 CVE-2019-20819: An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It allows stack consumption via n An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It allows stack consumption via nested function calls for XML parsing.
nvd
CVE-2019-20818P4HIGHCVSS 7.5fixed in 9.72020-06-04
CVE-2019-20818 [HIGH] CWE-770 CVE-2019-20818: An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It allows memory consumption beca An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It allows memory consumption because data is created for each page of an application level.
nvd
Foxitsoftware Phantompdf vulnerabilities | cvebase