cbcvebase.

Foxitsoftware Reader vulnerabilities

259 known vulnerabilities affecting foxitsoftware/reader.

Total CVEs
259
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH228MEDIUM13LOW7

Vulnerabilities

Page 12 of 13
CVE-2019-6728P3MEDIUMCVSS 6.5≤ 9.3.0.108262019-03-21
CVE-2019-6728 [MEDIUM] CWE-125 CVE-2019-6728: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from the lack of pro
nvd
CVE-2020-13806P3HIGHCVSS 7.5fixed in 9.7.22020-06-04
CVE-2020-13806 [HIGH] CWE-416 CVE-2020-13806: An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has a use-after-free because An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has a use-after-free because of JavaScript execution after a deletion or close operation.
nvd
CVE-2019-6735P3MEDIUMCVSS 6.5≤ 9.3.0.108262019-03-21
CVE-2019-6735 [MEDIUM] CWE-125 CVE-2019-6735: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from the lack of pro
nvd
CVE-2020-13810P3HIGHCVSS 7.5fixed in 9.7.22020-06-04
CVE-2020-13810 [HIGH] CWE-347 CVE-2020-13810: An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows signature validation An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows signature validation bypass via a modified file or a file with non-standard signatures.
nvd
CVE-2019-20837P3HIGHCVSS 7.5fixed in 9.52020-06-04
CVE-2019-20837 [HIGH] CWE-347 CVE-2019-20837: An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It allows signature validation by An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It allows signature validation bypass via a modified file or a file with non-standard signatures.
nvd
CVE-2020-13803P3HIGHCVSS 7.5fixed in 4.02020-06-04
CVE-2020-13803 [HIGH] CWE-347 CVE-2020-13803: An issue was discovered in Foxit PhantomPDF Mac and Foxit Reader for Mac before 4.0. It allows signa An issue was discovered in Foxit PhantomPDF Mac and Foxit Reader for Mac before 4.0. It allows signature validation bypass via a modified file or a file with non-standard signatures.
nvd
CVE-2018-3962P3HIGHCVSS 7.3≤ 9.2.0.92972018-10-02
CVE-2018-3962 [HIGH] CWE-416 CVE-2018-3962: A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the CreationDate property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enab
nvd
CVE-2019-6733P3MEDIUMCVSS 6.5≤ 9.3.0.108262019-03-21
CVE-2019-6733 [MEDIUM] CWE-125 CVE-2019-6733: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of PDF files. The issue results from the lack of p
nvd
CVE-2019-6734P3MEDIUMCVSS 6.5≤ 9.3.0.108262019-03-21
CVE-2019-6734 [MEDIUM] CWE-416 CVE-2019-6734: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the setInterval method. By performing actions i
nvd
CVE-2019-6732P3MEDIUMCVSS 6.5≤ 9.3.0.108262019-03-21
CVE-2019-6732 [MEDIUM] CWE-125 CVE-2019-6732: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the AFParseDateEx method. The issue results fro
nvd
CVE-2018-17699P3MEDIUMCVSS 6.5≤ 9.2.0.92972019-01-24
CVE-2018-17699 [MEDIUM] CWE-125 CVE-2018-17699: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from th
nvd
CVE-2020-13808P3HIGHCVSS 7.5fixed in 9.7.22020-06-04
CVE-2020-13808 [HIGH] CWE-835 CVE-2020-13808: An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption via crafted cross-reference stream data.
nvd
CVE-2020-13815P3HIGHCVSS 7.5fixed in 9.7.12020-06-04
CVE-2020-13815 [HIGH] CWE-400 CVE-2020-13815: An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It allows stack consumption via An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It allows stack consumption via a loop of an indirect object reference.
nvd
CVE-2019-20828P3HIGHCVSS 7.5fixed in 9.62020-06-04
CVE-2019-20828 [HIGH] CWE-120 CVE-2019-20828: An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has a buffer overflow because An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has a buffer overflow because a looping correction does not occur after JavaScript updates Field APs.
nvd
CVE-2019-20820P4HIGHCVSS 7.5fixed in 9.72020-06-04
CVE-2019-20820 [HIGH] CWE-476 CVE-2019-20820: An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It has a NULL pointer dereference An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It has a NULL pointer dereference during the parsing of file data.
nvd
CVE-2019-20819P4HIGHCVSS 7.5fixed in 9.72020-06-04
CVE-2019-20819 [HIGH] CWE-674 CVE-2019-20819: An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It allows stack consumption via n An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It allows stack consumption via nested function calls for XML parsing.
nvd
CVE-2019-20818P4HIGHCVSS 7.5fixed in 9.72020-06-04
CVE-2019-20818 [HIGH] CWE-770 CVE-2019-20818: An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It allows memory consumption beca An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It allows memory consumption because data is created for each page of an application level.
nvd
CVE-2018-17622P4MEDIUMCVSS 6.5≤ 9.2.0.92972018-10-29
CVE-2018-17622 [MEDIUM] CWE-125 CVE-2018-17622: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.1.0.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Calculate events. The issue results fr
nvd
CVE-2020-11493P4HIGHCVSS 8.1≤ 10.0.0.357982020-09-04
CVE-2020-11493 [HIGH] CWE-345 CVE-2020-11493: In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sens In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to Stream without concern for a crafted XObject.
nvd
CVE-2019-20829P4HIGHCVSS 7.5fixed in 9.62020-06-04
CVE-2019-20829 [HIGH] CWE-476 CVE-2019-20829: An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has a NULL pointer dereference An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has a NULL pointer dereference via FXSYS_wcslen in an Epub file.
nvd
Foxitsoftware Reader vulnerabilities | cvebase