cbcvebase.

Foxitsoftware Reader vulnerabilities

259 known vulnerabilities affecting foxitsoftware/reader.

Total CVEs
259
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH228MEDIUM13LOW7

Vulnerabilities

Page 13 of 13
CVE-2019-20817P4HIGHCVSS 7.5fixed in 9.72020-06-04
CVE-2019-20817 [HIGH] CWE-476 CVE-2019-20817: An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It has a NULL pointer dereference An issue was discovered in Foxit Reader and PhantomPDF before 9.7. It has a NULL pointer dereference.
nvd
CVE-2019-20826P4HIGHCVSS 7.5fixed in 3.32020-06-04
CVE-2019-20826 [HIGH] CWE-476 CVE-2019-20826: An issue was discovered in Foxit PhantomPDF Mac 3.3 and Foxit Reader for Mac before 3.3. It has a NU An issue was discovered in Foxit PhantomPDF Mac 3.3 and Foxit Reader for Mac before 3.3. It has a NULL pointer dereference.
nvd
CVE-2020-13807P4HIGHCVSS 7.5fixed in 9.7.22020-06-04
CVE-2020-13807 [HIGH] CWE-835 CVE-2020-13807: An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has circular reference misha An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has circular reference mishandling that causes a loop.
nvd
CVE-2020-13809P4HIGHCVSS 7.5fixed in 9.7.22020-06-04
CVE-2020-13809 [HIGH] CWE-400 CVE-2020-13809: An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption via long strings in the content stream.
nvd
CVE-2018-21236P4HIGHCVSS 7.5≤ 2.4.42020-06-04
CVE-2018-21236 [HIGH] CWE-476 CVE-2018-21236: An issue was discovered in Foxit Reader before 2.4.4. It has a NULL pointer dereference. An issue was discovered in Foxit Reader before 2.4.4. It has a NULL pointer dereference.
nvd
CVE-2018-21240P4HIGHCVSS 7.5fixed in 9.22020-06-04
CVE-2018-21240 [HIGH] CWE-400 CVE-2018-21240: An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows memory consumption via An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows memory consumption via an ArrayBuffer(0xfffffffe) call.
nvd
CVE-2019-13318P4MEDIUMCVSS 5.5≤ 9.5.0.207232019-10-04
CVE-2019-13318 [MEDIUM] CWE-134 CVE-2019-13318: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of the util.printf Javascript method. Th
nvd
CVE-2020-12247P4HIGHCVSS 7.1≤ 10.0.0.357982020-09-04
CVE-2020-12247 [HIGH] CWE-125 CVE-2020-12247: In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sens In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information from an out-of-bounds read because a text-string index continues to be used after splitting a string into two parts. A crash may also occur.
nvd
CVE-2016-8879P4MEDIUMCVSS 6.5≤ 8.0.52016-10-31
CVE-2016-8879 [MEDIUM] CWE-787 CVE-2016-8879: The thumbnail shell extension plugin (FoxitThumbnailHndlr_x86.dll) in Foxit Reader and PhantomPDF be The thumbnail shell extension plugin (FoxitThumbnailHndlr_x86.dll) in Foxit Reader and PhantomPDF before 8.1 on Windows allows remote attackers to cause a denial of service (out-of-bounds write and application crash) via a crafted JPEG2000 image embedded in a PDF document, aka an "Exploitable - Heap Corruption" issue.
nvd
CVE-2018-21239P4MEDIUMCVSS 5.3fixed in 9.22020-06-04
CVE-2018-21239 [MEDIUM] CWE-522 CVE-2018-21239: An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows NTLM credential theft v An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows NTLM credential theft via a GoToE or GoToR action.
nvd
CVE-2016-8334P4LOWCVSS 3.3v8.0.2.8052017-01-06
CVE-2016-8334 [LOW] CWE-125 CVE-2016-8334: A large out-of-bounds read on the heap vulnerability in Foxit PDF Reader can potentially be abused f A large out-of-bounds read on the heap vulnerability in Foxit PDF Reader can potentially be abused for information disclosure. Combined with another vulnerability, it can be used to leak heap memory layout and in bypassing ASLR.
nvd
CVE-2016-8875P4MEDIUMCVSS 5.3≤ 8.0.52016-10-31
CVE-2016-8875 [MEDIUM] CWE-125 CVE-2016-8875: The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image, aka "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at ConvertToPDF_x
nvd
CVE-2020-8852P4LOWCVSS 3.3≤ 9.7.0.294782020-02-14
CVE-2020-8852 [LOW] CWE-125 CVE-2020-8852: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of JPEG2000 files. The issue results from the
nvd
CVE-2020-15637P4LOWCVSS 3.3≤ 10.0.0.357982020-08-20
CVE-2020-15637 [LOW] CWE-416 CVE-2020-15637: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the SetLocalDescription method. By performing actions
nvd
CVE-2019-20835P4MEDIUMCVSS 4.3fixed in 9.52020-06-04
CVE-2019-20835 [MEDIUM] CVE-2019-20835: An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It has homograph mishandling. An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It has homograph mishandling.
nvd
CVE-2020-10901P4LOWCVSS 3.3≤ 9.7.1.295112020-04-22
CVE-2020-10901 [LOW] CWE-125 CVE-2020-10901: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects in PDF files. The issue re
nvd
CVE-2020-10905P4LOWCVSS 3.3≤ 9.7.1.295112020-04-22
CVE-2020-10905 [LOW] CWE-125 CVE-2020-10905: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of vertices in U3D objects. The issue res
nvd
CVE-2020-10903P4LOWCVSS 3.3≤ 9.7.1.295112020-04-22
CVE-2020-10903 [LOW] CWE-125 CVE-2020-10903: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in a PDF. The iss
nvd
CVE-2020-10894P4LOWCVSS 3.3≤ 9.7.1.295112020-04-22
CVE-2020-10894 [LOW] CWE-125 CVE-2020-10894: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in a PDF. The iss
nvd
Foxitsoftware Reader vulnerabilities | cvebase