Foxitsoftware Reader vulnerabilities
259 known vulnerabilities affecting foxitsoftware/reader.
Total CVEs
259
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH228MEDIUM13LOW7
Vulnerabilities
Page 6 of 13
CVE-2018-17701P3HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17701 [HIGH] CWE-125 CVE-2018-17701: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of JSON objects. The issue results from the lack
nvd
CVE-2018-17700P3HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17700 [HIGH] CWE-125 CVE-2018-17700: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Array.prototype.concat. The issue results fro
nvd
CVE-2018-5676P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-24
CVE-2018-5676 [HIGH] CVE-2018-5676: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before 9.1 and PhantomPDF before 9.1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of specially crafted pdf files wit
nvd
CVE-2018-3956P3HIGHCVSS 7.1≤ 9.3.0.108262019-01-30
CVE-2018-3956 [HIGH] CWE-125 CVE-2018-3956: An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attrib
An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Software's PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger an out-of-bounds read, which can disclose sensitive memory content and aid in exploitation when coupled with another vulnerability. An attacker needs to t
nvd
CVE-2018-17610P3CRITICALCVSS 9.8fixed in 9.32018-09-28
CVE-2018-17610 [CRITICAL] CWE-416 CVE-2018-17610: Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a d
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This relates to one of five distinct types of Annotation objects.
nvd
CVE-2018-17607P3CRITICALCVSS 9.8fixed in 9.32018-09-28
CVE-2018-17607 [CRITICAL] CWE-416 CVE-2018-17607: Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a d
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This relates to one of five distinct types of Annotation objects.
nvd
CVE-2018-17608P3CRITICALCVSS 9.8fixed in 9.32018-09-28
CVE-2018-17608 [CRITICAL] CWE-416 CVE-2018-17608: Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a d
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This relates to one of five distinct types of Annotation objects.
nvd
CVE-2018-17609P3CRITICALCVSS 9.8fixed in 9.32018-09-28
CVE-2018-17609 [CRITICAL] CWE-416 CVE-2018-17609: Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a d
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This relates to one of five distinct types of Annotation objects.
nvd
CVE-2018-17611P3CRITICALCVSS 9.8fixed in 9.32018-09-28
CVE-2018-17611 [CRITICAL] CWE-416 CVE-2018-17611: Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a d
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This relates to one of five distinct types of Annotation objects.
nvd
CVE-2018-5675P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-24
CVE-2018-5675 [HIGH] CWE-787 CVE-2018-5675: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before 9.1 and PhantomPDF before 9.1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of specially crafted pdf f
nvd
CVE-2018-17671P3HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17671 [HIGH] CWE-125 CVE-2018-17671: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the Lower method of a XFA object. The is
nvd
CVE-2018-5680P3HIGHCVSS 8.8≤ 9.0.1.10492018-05-24
CVE-2018-5680 [HIGH] CVE-2018-5680: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before 9.1 and PhantomPDF before 9.1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of specially crafted pdf files wit
nvd
CVE-2016-8877P3HIGHCVSS 8.8≤ 8.0.52016-10-31
CVE-2016-8877 [HIGH] CWE-787 CVE-2016-8877: Heap buffer overflow (Out-of-Bounds write) vulnerability in Foxit Reader and PhantomPDF before 8.1 o
Heap buffer overflow (Out-of-Bounds write) vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows allows remote attackers to execute arbitrary code via a crafted JPEG2000 image embedded in a PDF document, aka a "corrupted suffix pattern" issue.
nvd
CVE-2020-10890P3HIGHCVSS 8.8≤ 9.7.1.295112020-04-22
CVE-2020-10890 [HIGH] CWE-352 CVE-2020-10890: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the communication API. The issue lies in the handling of the
nvd
CVE-2020-10892P3HIGHCVSS 8.8≤ 9.7.1.295112020-04-22
CVE-2020-10892 [HIGH] CWE-352 CVE-2020-10892: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the communication API. The issue lies in the handling of the
nvd
CVE-2019-5031P3HIGHCVSS 8.8≤ 9.4.1.168282019-10-02
CVE-2019-5031 [HIGH] CWE-703 CVE-2019-5031: An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's F
An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.4.1.16828. A specially crafted PDF document can trigger an out-of-memory condition which isn't handled properly, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger th
nvd
CVE-2020-8857P3HIGHCVSS 7.8≤ 9.7.0.294782020-02-14
CVE-2020-8857 [HIGH] CWE-416 CVE-2020-8857: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of form Annotation objects within AcroForms. The issue
nvd
CVE-2020-8855P3HIGHCVSS 7.8≤ 9.7.0.294782020-02-14
CVE-2020-8855 [HIGH] CWE-416 CVE-2020-8855: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.2947. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the fxhtml2pdf.exe module. The issue results from the lack of va
nvd
CVE-2018-17686P3MEDIUMCVSS 6.5≤ 9.2.0.92972019-01-24
CVE-2018-17686 [MEDIUM] CWE-125 CVE-2018-17686: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of BMP images. The issue results from t
nvd
CVE-2019-13315P3HIGHCVSS 7.8≤ 9.5.0.207232019-10-04
CVE-2019-13315 [HIGH] CWE-416 CVE-2019-13315: This vulnerability allows remote atackers to execute arbitrary code on affected installations of Fox
This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the removeField method. The issue results from the lack of validat
nvd