Foxitsoftware Reader vulnerabilities
259 known vulnerabilities affecting foxitsoftware/reader.
Total CVEs
259
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH228MEDIUM13LOW7
Vulnerabilities
Page 11 of 13
CVE-2018-20316P3HIGHCVSS 8.1fixed in 9.52021-01-07
CVE-2018-20316 [HIGH] CVE-2018-20316: Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race c
Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read, a different issue than CVE-2018-20310 because of a different opcode.
nvd
CVE-2019-20830P3CRITICALCVSS 9.8fixed in 9.62020-06-04
CVE-2019-20830 [CRITICAL] CWE-787 CVE-2019-20830: An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has an out-of-bounds write whe
An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has an out-of-bounds write when Internet Explorer is used.
nvd
CVE-2016-8856P3HIGHCVSS 7.8≤ 2.1.0.0804≤ 2.1.0.08052016-10-31
CVE-2016-8856 [HIGH] CWE-275 CVE-2016-8856: Foxit Reader for Mac 2.1.0.0804 and earlier and Foxit Reader for Linux 2.1.0.0805 and earlier suffer
Foxit Reader for Mac 2.1.0.0804 and earlier and Foxit Reader for Linux 2.1.0.0805 and earlier suffered from a vulnerability where weak file permissions could be exploited by attackers to execute arbitrary code. After the installation, Foxit Reader's core files were world-writable by default, allowing an attacker to overwrite them with backdoor code, whi
nvd
CVE-2020-13805P3CRITICALCVSS 9.8fixed in 9.7.22020-06-04
CVE-2020-13805 [CRITICAL] CWE-307 CVE-2020-13805: An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has brute-force attack misha
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has brute-force attack mishandling because the CAS service lacks a limit on login failures.
nvd
CVE-2018-16293P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-08
CVE-2018-16293 [HIGH] CVE-2018-16293: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16292, CVE-2018-16294, CVE-2018-16295, CVE-2018-16296, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resul
nvd
CVE-2018-16294P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-08
CVE-2018-16294 [HIGH] CVE-2018-16294: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16292, CVE-2018-16293, CVE-2018-16295, CVE-2018-16296, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resul
nvd
CVE-2018-16297P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-08
CVE-2018-16297 [HIGH] CVE-2018-16297: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16292, CVE-2018-16293, CVE-2018-16294, CVE-2018-16295, and CVE-2018-16296. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resul
nvd
CVE-2018-16292P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-08
CVE-2018-16292 [HIGH] CVE-2018-16292: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16293, CVE-2018-16294, CVE-2018-16295, CVE-2018-16296, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resul
nvd
CVE-2018-16296P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-08
CVE-2018-16296 [HIGH] CVE-2018-16296: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16292, CVE-2018-16293, CVE-2018-16294, CVE-2018-16295, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resul
nvd
CVE-2018-16291P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-08
CVE-2018-16291 [HIGH] CWE-416 CVE-2018-16291: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16292, CVE-2018-16293, CVE-2018-16294, CVE-2018-16295, CVE-2018-16296, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reuse
nvd
CVE-2018-16295P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-08
CVE-2018-16295 [HIGH] CVE-2018-16295: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16292, CVE-2018-16293, CVE-2018-16294, CVE-2018-16296, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resul
nvd
CVE-2020-13814P3CRITICALCVSS 9.8fixed in 9.7.12020-06-04
CVE-2020-13814 [CRITICAL] CWE-416 CVE-2020-13814: An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It has a use-after-free via a d
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It has a use-after-free via a document that lacks a dictionary.
nvd
CVE-2018-17781P3HIGHCVSS 7.5≤ 9.2.0.92972018-09-29
CVE-2018-17781 [HIGH] CWE-200 CVE-2018-17781: Foxit PhantomPDF and Reader before 9.3 allow remote attackers to trigger Uninitialized Object Inform
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to trigger Uninitialized Object Information Disclosure because creation of ArrayBuffer and DataView objects is mishandled.
nvd
CVE-2019-17183P3HIGHCVSS 7.5fixed in 9.6.0.251142019-10-04
CVE-2019-17183 [HIGH] CWE-772 CVE-2019-17183: Foxit Reader before 9.7 allows an Access Violation and crash if insufficient memory exists.
Foxit Reader before 9.7 allows an Access Violation and crash if insufficient memory exists.
nvd
CVE-2018-3957P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-02
CVE-2018-3957 [HIGH] CWE-416 CVE-2018-3957: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Keywords property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled,
nvd
CVE-2018-3958P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-02
CVE-2018-3958 [HIGH] CWE-416 CVE-2018-3958: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Subject property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled,
nvd
CVE-2018-3959P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-02
CVE-2018-3959 [HIGH] CWE-416 CVE-2018-3959: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Author property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, v
nvd
CVE-2018-3961P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-02
CVE-2018-3961 [HIGH] CWE-416 CVE-2018-3961: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Creator property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled,
nvd
CVE-2018-3960P3HIGHCVSS 7.8≤ 9.2.0.92972018-10-02
CVE-2018-3960 [HIGH] CWE-416 CVE-2018-3960: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Producer property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled,
nvd
CVE-2019-20836P3HIGHCVSS 7.5fixed in 9.52020-06-04
CVE-2019-20836 [HIGH] CWE-200 CVE-2019-20836: An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It has mishandling of cloud crede
An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It has mishandling of cloud credentials, as demonstrated by Google Drive.
nvd