Foxitsoftware Phantompdf vulnerabilities
549 known vulnerabilities affecting foxitsoftware/phantompdf.
Total CVEs
549
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL26HIGH438MEDIUM68LOW17
Vulnerabilities
Page 27 of 28
CVE-2018-21237P4MEDIUMCVSS 5.3fixed in 8.3.72020-06-04
CVE-2018-21237 [MEDIUM] CWE-522 CVE-2018-21237: An issue was discovered in Foxit PhantomPDF before 8.3.7. It allows NTLM credential theft via a GoTo
An issue was discovered in Foxit PhantomPDF before 8.3.7. It allows NTLM credential theft via a GoToE or GoToR action.
nvd
CVE-2015-3633P4MEDIUMCVSS 5.0≤ 7.1.3.320v7.1.0.3062015-05-01
CVE-2015-3633 [MEDIUM] CWE-119 CVE-2015-3633: Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denia
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via vectors related to digital signatures.
nvd
CVE-2017-6883P4MEDIUMCVSS 4.7≤ 8.2.0.21922017-03-14
CVE-2017-6883 [MEDIUM] CWE-125 CVE-2017-6883: The ConvertToPDF plugin in Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 on Windows, when th
The ConvertToPDF plugin in Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image. The vulnerability could lead to information disclosure; an attacker can leverage this in conjunction with
nvd
CVE-2020-28203P4MEDIUMCVSS 5.5fixed in 10.1.0.375272020-12-15
CVE-2020-28203 [MEDIUM] CWE-476 CVE-2020-28203: An issue was discovered in Foxit Reader and PhantomPDF 10.1.0.37527 and earlier. There is a null poi
An issue was discovered in Foxit Reader and PhantomPDF 10.1.0.37527 and earlier. There is a null pointer access/dereference while opening a crafted PDF file, leading the application to crash (denial of service).
nvd
CVE-2021-33795P4MEDIUMCVSS 5.5fixed in 10.1.42021-07-09
CVE-2021-33795 [MEDIUM] CWE-755 CVE-2021-33795: Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 produce incorrect PDF document signatures be
Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 produce incorrect PDF document signatures because the certificate name, document owner, and signature author are mishandled.
nvd
CVE-2016-8875P4MEDIUMCVSS 5.3≤ 8.0.52016-10-31
CVE-2016-8875 [MEDIUM] CWE-125 CVE-2016-8875: The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is
The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image, aka "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at ConvertToPDF_x
nvd
CVE-2020-26536P4MEDIUMCVSS 5.5fixed in 10.12020-10-02
CVE-2020-26536 [MEDIUM] CWE-476 CVE-2020-26536: An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is a NULL pointer derefere
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is a NULL pointer dereference via a crafted PDF document.
nvd
CVE-2019-20832P4MEDIUMCVSS 4.3fixed in 8.3.102020-06-04
CVE-2019-20832 [MEDIUM] CVE-2019-20832: An issue was discovered in Foxit PhantomPDF before 8.3.10. It has homograph mishandling.
An issue was discovered in Foxit PhantomPDF before 8.3.10. It has homograph mishandling.
nvd
CVE-2021-27263P4LOWCVSS 3.3≤ 10.1.0.375272021-03-30
CVE-2021-27263 [LOW] CWE-125 CVE-2021-27263: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in PDF files. Th
nvd
CVE-2019-5006P4MEDIUMCVSS 5.5fixed in 9.42019-01-03
CVE-2019-5006 [MEDIUM] CWE-476 CVE-2019-5006: An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. It is a NULL pointer d
An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. It is a NULL pointer dereference during PDF parsing.
nvd
CVE-2020-8852P4LOWCVSS 3.3≤ 9.7.0.294552020-02-14
CVE-2020-8852 [LOW] CWE-125 CVE-2020-8852: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of JPEG2000 files. The issue results from the
nvd
CVE-2021-31446P4LOWCVSS 3.3≤ 9.7.5.29616≥ 10.0.0.0, ≤ 10.1.3.375982021-05-07
CVE-2021-31446 [LOW] CWE-125 CVE-2021-31446: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in PDF files. The is
nvd
CVE-2021-31444P4LOWCVSS 3.3≤ 9.7.5.29616≥ 10.0.0.0, ≤ 10.1.3.375982021-05-07
CVE-2021-31444 [LOW] CWE-125 CVE-2021-31444: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in PDF files. The is
nvd
CVE-2021-31448P4LOWCVSS 3.3≤ 9.7.5.29616≥ 10.0.0.0, ≤ 10.1.3.375982021-05-07
CVE-2021-31448 [LOW] CWE-125 CVE-2021-31448: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in PDF files. The is
nvd
CVE-2021-31445P4LOWCVSS 3.3≤ 9.7.5.29616≥ 10.0.0.0, ≤ 10.1.3.375982021-05-07
CVE-2021-31445 [LOW] CWE-125 CVE-2021-31445: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in PDF files. The is
nvd
CVE-2021-31443P4LOWCVSS 3.3≤ 9.7.5.29616≥ 10.0.0.0, ≤ 10.1.3.375982021-05-07
CVE-2021-31443 [LOW] CWE-125 CVE-2021-31443: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in PDF files. The is
nvd
CVE-2021-31447P4LOWCVSS 3.3≤ 9.7.5.29616≥ 10.0.0.0, ≤ 10.1.3.375982021-05-07
CVE-2021-31447 [LOW] CWE-125 CVE-2021-31447: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in PDF files. The is
nvd
CVE-2016-4062P4MEDIUMCVSS 5.5≤ 7.3.0.1182016-04-22
CVE-2016-4062 [MEDIUM] CWE-19 CVE-2016-4062: Foxit Reader and PhantomPDF before 7.3.4 on Windows improperly report format errors recursively, whi
Foxit Reader and PhantomPDF before 7.3.4 on Windows improperly report format errors recursively, which allows remote attackers to cause a denial of service (application hang) via a crafted PDF.
nvd
CVE-2019-5005P4MEDIUMCVSS 5.5fixed in 9.42019-01-03
CVE-2019-5005 [MEDIUM] CWE-787 CVE-2019-5005: An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. They allowed Denial of
An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. They allowed Denial of Service (application crash) via image data, because two bytes are written to the end of the allocated memory without judging whether this will cause corruption.
nvd
CVE-2020-15637P4LOWCVSS 3.3≤ 10.0.0.357982020-08-20
CVE-2020-15637 [LOW] CWE-416 CVE-2020-15637: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the SetLocalDescription method. By performing actions
nvd