cbcvebase.

Foxitsoftware Phantompdf vulnerabilities

549 known vulnerabilities affecting foxitsoftware/phantompdf.

Total CVEs
549
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL26HIGH438MEDIUM68LOW17

Vulnerabilities

Page 26 of 28
CVE-2018-21240P4HIGHCVSS 7.5fixed in 9.22020-06-04
CVE-2018-21240 [HIGH] CWE-400 CVE-2018-21240: An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows memory consumption via An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows memory consumption via an ArrayBuffer(0xfffffffe) call.
nvd
CVE-2016-4065P4HIGHCVSS 7.8≤ 7.3.0.1182016-04-22
CVE-2016-4065 [HIGH] CWE-119 CVE-2016-4065: The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 7.3.4 on Windows, when the gflags app The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 7.3.4 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted (1) JPEG, (2) GIF, or (3) BMP image.
nvd
CVE-2019-13318P4MEDIUMCVSS 5.5≤ 8.3.10.42705≥ 9.0, ≤ 9.5.0.207232019-10-04
CVE-2019-13318 [MEDIUM] CWE-134 CVE-2019-13318: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of the util.printf Javascript method. Th
nvd
CVE-2016-4060P4HIGHCVSS 7.5≤ 7.3.0.1182016-04-22
CVE-2016-4060 [HIGH] CVE-2016-4060: Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote at Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2019-6773P4MEDIUMCVSS 5.5≤ 8.3.9.41099≥ 9.0.0, ≤ 9.4.1.168282019-06-03
CVE-2019-6773 [MEDIUM] CWE-416 CVE-2019-6773: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the richValue property of a Field objec
nvd
CVE-2016-4061P4HIGHCVSS 7.5≤ 7.3.0.1182016-04-22
CVE-2016-4061 [HIGH] CWE-20 CVE-2016-4061: Foxit Reader and PhantomPDF before 7.3.4 on Windows allow remote attackers to cause a denial of serv Foxit Reader and PhantomPDF before 7.3.4 on Windows allow remote attackers to cause a denial of service (application crash) via a crafted content stream.
nvd
CVE-2019-6756P4MEDIUMCVSS 5.5≤ 8.3.9.41099≥ 9.0.0, ≤ 9.4.1.168282019-06-03
CVE-2019-6756 [MEDIUM] CWE-416 CVE-2019-6756: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF 9.4.0.16811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of HTML files. The issue results from t
nvd
CVE-2019-6770P4MEDIUMCVSS 5.5≤ 8.3.9.41099≥ 9.0.0, ≤ 9.4.1.168282019-06-03
CVE-2019-6770 [MEDIUM] CWE-416 CVE-2019-6770: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the resetForm method when processing AcroForms. The iss
nvd
CVE-2019-6771P4MEDIUMCVSS 5.5≤ 8.3.9.41099≥ 9.0.0, ≤ 9.4.1.168282019-06-03
CVE-2019-6771 [MEDIUM] CWE-416 CVE-2019-6771: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 2019.010.20098. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the value property of a Field object
nvd
CVE-2019-6758P4MEDIUMCVSS 5.5≤ 8.3.9.41099≥ 9.0.0, ≤ 9.4.1.168282019-06-03
CVE-2019-6758 [MEDIUM] CWE-416 CVE-2019-6758: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.4.16811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within ConvertToPDF_x86.dll. The issue results from the lack of
nvd
CVE-2019-6772P4MEDIUMCVSS 5.5≤ 8.3.9.41099≥ 9.0.0, ≤ 9.4.1.168282019-06-03
CVE-2019-6772 [MEDIUM] CWE-416 CVE-2019-6772: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 2019.010.20098. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the removeField method when processing AcroForms. Th
nvd
CVE-2019-6766P4MEDIUMCVSS 5.5≤ 8.3.9.41099≥ 9.0.0, ≤ 9.4.1.168282019-06-03
CVE-2019-6766 [MEDIUM] CWE-416 CVE-2019-6766: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the removeField method when processing AcroForms. The i
nvd
CVE-2019-6752P4MEDIUMCVSS 5.5≤ 8.3.9.41099≥ 9.0.0, ≤ 9.4.1.168282019-06-03
CVE-2019-6752 [MEDIUM] CWE-125 CVE-2019-6752: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF 9.3.10826. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF documents. The issue results from
nvd
CVE-2020-12247P4HIGHCVSS 7.1≤ 9.7.2.29539≤ 10.0.0.357982020-09-04
CVE-2020-12247 [HIGH] CWE-125 CVE-2020-12247: In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sens In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information from an out-of-bounds read because a text-string index continues to be used after splitting a string into two parts. A crash may also occur.
nvd
CVE-2016-8879P4MEDIUMCVSS 6.5≤ 8.0.52016-10-31
CVE-2016-8879 [MEDIUM] CWE-787 CVE-2016-8879: The thumbnail shell extension plugin (FoxitThumbnailHndlr_x86.dll) in Foxit Reader and PhantomPDF be The thumbnail shell extension plugin (FoxitThumbnailHndlr_x86.dll) in Foxit Reader and PhantomPDF before 8.1 on Windows allows remote attackers to cause a denial of service (out-of-bounds write and application crash) via a crafted JPEG2000 image embedded in a PDF document, aka an "Exploitable - Heap Corruption" issue.
nvd
CVE-2019-17143P4MEDIUMCVSS 4.3v9.6.0.251142019-10-25
CVE-2019-17143 [MEDIUM] CWE-416 CVE-2019-17143: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DWG files. The issue results from th
nvd
CVE-2018-18688P4MEDIUMCVSS 5.3≥ 9.0, < 9.4v8.3.92021-01-07
CVE-2018-18688 [MEDIUM] CWE-347 CVE-2018-18688: The Portable Document Format (PDF) specification does not provide any information regarding the conc The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates are displayed to the user witho
nvd
CVE-2019-5007P4HIGHCVSS 7.1fixed in 9.42019-01-03
CVE-2019-5007 [HIGH] CWE-125 CVE-2019-5007: An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. It is an Out-of-Bounds An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. It is an Out-of-Bounds Read Information Disclosure and crash due to a NULL pointer dereference when reading TIFF data during TIFF parsing.
nvd
CVE-2018-21243P4MEDIUMCVSS 6.5fixed in 8.3.62020-06-04
CVE-2018-21243 [MEDIUM] CWE-434 CVE-2018-21243: An issue was discovered in Foxit PhantomPDF before 8.3.6. It has COM object mishandling when Microso An issue was discovered in Foxit PhantomPDF before 8.3.6. It has COM object mishandling when Microsoft Word is used.
nvd
CVE-2018-21239P4MEDIUMCVSS 5.3fixed in 9.22020-06-04
CVE-2018-21239 [MEDIUM] CWE-522 CVE-2018-21239: An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows NTLM credential theft v An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows NTLM credential theft via a GoToE or GoToR action.
nvd
Foxitsoftware Phantompdf vulnerabilities | cvebase