Foxitsoftware Phantompdf vulnerabilities

549 known vulnerabilities affecting foxitsoftware/phantompdf.

Total CVEs
549
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL26HIGH438MEDIUM68LOW17

Vulnerabilities

Page 28 of 28
CVE-2016-4065HIGHCVSS 7.8≤ 7.3.0.1182016-04-22
CVE-2016-4065 [HIGH] CWE-119 CVE-2016-4065: The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 7.3.4 on Windows, when the gflags app The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 7.3.4 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted (1) JPEG, (2) GIF, or (3) BMP image.
nvd
CVE-2016-4059HIGHCVSS 7.8≤ 7.3.0.1182016-04-22
CVE-2016-4059 [HIGH] CVE-2016-4059: Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote at Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via a crafted FlateDecode stream in a PDF document.
nvd
CVE-2016-4061HIGHCVSS 7.5≤ 7.3.0.1182016-04-22
CVE-2016-4061 [HIGH] CWE-20 CVE-2016-4061: Foxit Reader and PhantomPDF before 7.3.4 on Windows allow remote attackers to cause a denial of serv Foxit Reader and PhantomPDF before 7.3.4 on Windows allow remote attackers to cause a denial of service (application crash) via a crafted content stream.
nvd
CVE-2016-4063HIGHCVSS 7.8≤ 7.3.0.1182016-04-22
CVE-2016-4063 [HIGH] CVE-2016-4063: Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote at Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via an object with a revision number of -1 in a PDF document.
nvd
CVE-2016-4062MEDIUMCVSS 5.5≤ 7.3.0.1182016-04-22
CVE-2016-4062 [MEDIUM] CWE-19 CVE-2016-4062: Foxit Reader and PhantomPDF before 7.3.4 on Windows improperly report format errors recursively, whi Foxit Reader and PhantomPDF before 7.3.4 on Windows improperly report format errors recursively, which allows remote attackers to cause a denial of service (application hang) via a crafted PDF.
nvd
CVE-2015-8580MEDIUMCVSS 6.8≤ 7.2.0.7222015-12-16
CVE-2015-8580 [MEDIUM] CVE-2015-8580: Multiple use-after-free vulnerabilities in the (1) Print method and (2) App object handling in Foxit Multiple use-after-free vulnerabilities in the (1) Print method and (2) App object handling in Foxit Reader before 7.2.2 and Foxit PhantomPDF before 7.2.2 allow remote attackers to execute arbitrary code via a crafted PDF document.
nvd
CVE-2015-3633MEDIUMCVSS 5.0≤ 7.1.3.320v7.1.0.3062015-05-01
CVE-2015-3633 [MEDIUM] CWE-119 CVE-2015-3633: Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denia Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via vectors related to digital signatures.
nvd
CVE-2015-3632MEDIUMCVSS 4.3PoC≤ 7.1.3.3202015-05-01
CVE-2015-3632 [MEDIUM] CWE-119 CVE-2015-3632: Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denia Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted GIF in a PDF file.
nvd
CVE-2015-2790MEDIUMCVSS 4.3PoC≤ 7.0.6.11262015-03-30
CVE-2015-2790 [MEDIUM] CWE-20 CVE-2015-2790: Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted (1) Ubyte Size in a DataSubBlock structure or (2) LZWMinimumCodeSize in a GIF image.
nvd