cbcvebase.

Foxitsoftware Phantompdf vulnerabilities

549 known vulnerabilities affecting foxitsoftware/phantompdf.

Total CVEs
549
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL26HIGH438MEDIUM68LOW17

Vulnerabilities

Page 25 of 28
CVE-2018-1179P4MEDIUMCVSS 6.5≤ 9.0.1.10492018-05-17
CVE-2018-1179 [MEDIUM] CWE-125 CVE-2018-1179: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DataSubBlock structures in GIF images. T
nvd
CVE-2018-10485P4MEDIUMCVSS 6.5≤ 9.0.1.10492018-05-17
CVE-2018-10485 [MEDIUM] CWE-125 CVE-2018-10485: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within U3D Texture Height structures. The issue results from
nvd
CVE-2018-10480P4MEDIUMCVSS 6.5≤ 9.0.1.10492018-05-17
CVE-2018-10480 [MEDIUM] CWE-125 CVE-2018-10480: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the U3D Node Name buffer. The issue r
nvd
CVE-2019-14208P4HIGHCVSS 7.5fixed in 8.3.102019-07-21
CVE-2019-14208 [HIGH] CWE-476 CVE-2019-14208: An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to a NUL An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to a NULL pointer dereference and crash when getting a PDF object from a document, or parsing a certain portfolio that contains a null dictionary.
nvd
CVE-2019-14214P4HIGHCVSS 7.5fixed in 8.3.102019-07-21
CVE-2019-14214 [HIGH] CVE-2019-14214: An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to a Jav An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to a JavaScript Denial of Service when deleting pages in a document that contains only one page by calling a "t.hidden = true" function.
nvd
CVE-2021-38571P4HIGHCVSS 7.8fixed in 9.7.5.29616≥ 10.0.0.0, < 10.1.42021-08-11
CVE-2021-38571 [HIGH] CWE-427 CVE-2021-38571: An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka C An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and CNVD-C-2021-68502.
nvd
CVE-2018-9976P4MEDIUMCVSS 6.5≤ 9.0.1.10492018-05-17
CVE-2018-9976 [MEDIUM] CWE-125 CVE-2018-9976: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of Texture objects in U3D files. The issue
nvd
CVE-2018-9978P4MEDIUMCVSS 6.5≤ 9.0.1.10492018-05-17
CVE-2018-9978 [MEDIUM] CWE-125 CVE-2018-9978: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the la
nvd
CVE-2018-10492P4MEDIUMCVSS 6.5≤ 9.0.1.10492018-05-17
CVE-2018-10492 [MEDIUM] CWE-125 CVE-2018-10492: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Clod Progressive Mesh Continuation
nvd
CVE-2018-9984P4MEDIUMCVSS 6.5≤ 9.0.1.10492018-05-17
CVE-2018-9984 [MEDIUM] CWE-125 CVE-2018-9984: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of Texture Image Channels objects in U3D fi
nvd
CVE-2018-10493P4MEDIUMCVSS 6.5≤ 9.0.1.10492018-05-17
CVE-2018-10493 [MEDIUM] CWE-125 CVE-2018-10493: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of the U3D Final Maximum Resolution attrib
nvd
CVE-2018-10476P4MEDIUMCVSS 6.5≤ 9.0.1.10492018-05-17
CVE-2018-10476 [MEDIUM] CWE-125 CVE-2018-10476: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Model Node structures. The issue r
nvd
CVE-2018-10479P4MEDIUMCVSS 6.5≤ 9.0.1.10492018-05-17
CVE-2018-10479 [MEDIUM] CWE-125 CVE-2018-10479: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Key Frame structures. The issue re
nvd
CVE-2018-9979P4MEDIUMCVSS 6.5≤ 9.0.1.10492018-05-17
CVE-2018-9979 [MEDIUM] CWE-125 CVE-2018-9979: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of Texture Continuation objects in U3D file
nvd
CVE-2018-10475P4MEDIUMCVSS 6.5≤ 9.0.1.10492018-05-17
CVE-2018-10475 [MEDIUM] CWE-125 CVE-2018-10475: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Light Node structures. The issue r
nvd
CVE-2018-10486P4MEDIUMCVSS 6.5≤ 9.0.1.10492018-05-17
CVE-2018-10486 [MEDIUM] CWE-125 CVE-2018-10486: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of the U3D Image Index. The issue results
nvd
CVE-2018-10487P4MEDIUMCVSS 6.5≤ 9.0.1.10492018-05-17
CVE-2018-10487 [MEDIUM] CWE-125 CVE-2018-10487: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files embedded inside PDF document
nvd
CVE-2018-9980P4MEDIUMCVSS 6.5≤ 9.0.1.10492018-05-17
CVE-2018-9980 [MEDIUM] CWE-125 CVE-2018-9980: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the la
nvd
CVE-2018-10482P4MEDIUMCVSS 6.5≤ 9.0.1.10492018-05-17
CVE-2018-10482 [MEDIUM] CWE-125 CVE-2018-10482: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the U3D Texture Image Format object. The issue result
nvd
CVE-2018-21238P4HIGHCVSS 7.5fixed in 8.3.72020-06-04
CVE-2018-21238 [HIGH] CWE-400 CVE-2018-21238: An issue was discovered in Foxit PhantomPDF before 8.3.7. It allows memory consumption via an ArrayB An issue was discovered in Foxit PhantomPDF before 8.3.7. It allows memory consumption via an ArrayBuffer(0xfffffffe) call.
nvd
Foxitsoftware Phantompdf vulnerabilities | cvebase