cbcvebase.

Foxitsoftware Reader vulnerabilities

259 known vulnerabilities affecting foxitsoftware/reader.

Total CVEs
259
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH228MEDIUM13LOW7

Vulnerabilities

Page 10 of 13
CVE-2018-3964P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-03
CVE-2018-3964 [HIGH] CWE-416 CVE-2018-3964: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxi An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerabi
nvd
CVE-2020-8853P3HIGHCVSS 7.8≤ 9.7.0.294782020-02-14
CVE-2020-8853 [HIGH] CWE-787 CVE-2020-8853: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the conversion of HTML files to PDF. The issue results from the
nvd
CVE-2020-10895P3HIGHCVSS 7.8≤ 9.7.1.295112020-04-22
CVE-2020-10895 [HIGH] CWE-125 CVE-2020-10895: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects in PDF files. The issue results f
nvd
CVE-2020-10904P3HIGHCVSS 7.8≤ 9.7.1.295112020-04-22
CVE-2020-10904 [HIGH] CWE-787 CVE-2020-10904: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects in PDF files. The issue results f
nvd
CVE-2020-10897P3HIGHCVSS 7.8≤ 9.7.1.295112020-04-22
CVE-2020-10897 [HIGH] CWE-787 CVE-2020-10897: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects in PDF files. The issue results f
nvd
CVE-2020-10898P3HIGHCVSS 7.8≤ 9.7.1.295112020-04-22
CVE-2020-10898 [HIGH] CWE-125 CVE-2020-10898: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects in PDF files. The issue results f
nvd
CVE-2020-10902P3HIGHCVSS 7.8≤ 9.7.1.295112020-04-22
CVE-2020-10902 [HIGH] CWE-125 CVE-2020-10902: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects in PDF files. The issue results f
nvd
CVE-2019-13329P3HIGHCVSS 7.8≤ 9.6.0.251142019-10-03
CVE-2019-13329 [HIGH] CWE-843 CVE-2019-13329: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of TIF files. The issue results from the lack of proper va
nvd
CVE-2018-20310P3HIGHCVSS 8.1fixed in 9.52021-01-07
CVE-2018-20310 [HIGH] CWE-125 CVE-2018-20310: Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race c Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read.
nvd
CVE-2018-20314P3HIGHCVSS 8.1fixed in 9.52021-01-07
CVE-2018-20314 [HIGH] CWE-125 CVE-2018-20314: Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCheckLicence ra Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCheckLicence race condition that can cause a stack-based buffer overflow or an out-of-bounds read.
nvd
CVE-2018-20313P3HIGHCVSS 8.1fixed in 9.52021-01-07
CVE-2018-20313 [HIGH] CWE-125 CVE-2018-20313: Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyPreviewAction r Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyPreviewAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read.
nvd
CVE-2018-20311P3HIGHCVSS 8.1fixed in 9.52021-01-07
CVE-2018-20311 [HIGH] CWE-125 CVE-2018-20311: Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCPDFAction race Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCPDFAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read.
nvd
CVE-2018-20309P3HIGHCVSS 8.1fixed in 9.52021-01-07
CVE-2018-20309 [HIGH] CWE-125 CVE-2018-20309: Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyGetAppEdition r Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyGetAppEdition race condition that can cause a stack-based buffer overflow or an out-of-bounds read.
nvd
CVE-2018-20315P3HIGHCVSS 8.1fixed in 9.52021-01-07
CVE-2018-20315 [HIGH] CWE-362 CVE-2018-20315: Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a race condition that Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a race condition that can cause a stack-based buffer overflow or an out-of-bounds read.
nvd
CVE-2016-8876P3HIGHCVSS 7.5≤ 8.0.52016-10-31
CVE-2016-8876 [HIGH] CWE-125 CVE-2016-8876: Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gfla Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF image embedded in the XFA stream in a PDF document, aka "Read Access Violation starting at FoxitReader."
nvd
CVE-2018-3966P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-03
CVE-2018-3966 [HIGH] CWE-416 CVE-2018-3966: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxi An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerabi
nvd
CVE-2018-3967P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-03
CVE-2018-3967 [HIGH] CWE-416 CVE-2018-3967: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxi An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerabi
nvd
CVE-2018-3965P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-03
CVE-2018-3965 [HIGH] CWE-416 CVE-2018-3965: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxi An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerabi
nvd
CVE-2018-3940P3HIGHCVSS 8.8≤ 9.2.0.92972018-10-08
CVE-2018-3940 [HIGH] CWE-416 CVE-2018-3940: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused. An attacker needs to trick the user to open the malicious file to trigger.
nvd
CVE-2018-20312P3HIGHCVSS 8.1fixed in 9.52021-01-07
CVE-2018-20312 [HIGH] CVE-2018-20312: Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race c Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read, a different issue than CVE-2018-20310 because of a different opcode.
nvd
Foxitsoftware Reader vulnerabilities | cvebase