Foxitsoftware Reader vulnerabilities

259 known vulnerabilities affecting foxitsoftware/reader.

Total CVEs
259
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH228MEDIUM13LOW7

Vulnerabilities

Page 6 of 13
CVE-2019-13328HIGHCVSS 7.8≤ 9.6.0.251142019-10-03
CVE-2019-13328 [HIGH] CWE-416 CVE-2019-13328: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of fields within Acroform objects. The issue resul
nvd
CVE-2019-13329HIGHCVSS 7.8≤ 9.6.0.251142019-10-03
CVE-2019-13329 [HIGH] CWE-843 CVE-2019-13329: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of TIF files. The issue results from the lack of proper va
nvd
CVE-2019-13332HIGHCVSS 7.8≤ 9.6.0.251142019-10-03
CVE-2019-13332 [HIGH] CWE-416 CVE-2019-13332: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of templates in XFA forms. The issue results from
nvd
CVE-2019-13331HIGHCVSS 7.8≤ 9.6.0.251142019-10-03
CVE-2019-13331 [HIGH] CWE-125 CVE-2019-13331: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPG files. The issue results from the lack of prop
nvd
CVE-2019-5031HIGHCVSS 8.8≤ 9.4.1.168282019-10-02
CVE-2019-5031 [HIGH] CWE-703 CVE-2019-5031: An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's F An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.4.1.16828. A specially crafted PDF document can trigger an out-of-memory condition which isn't handled properly, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger th
nvd
CVE-2019-6731HIGHCVSS 8.8≤ 9.3.0.108262019-03-21
CVE-2019-6731 [HIGH] CWE-125 CVE-2019-6731: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the conversion of HTML files to PDF. The issue results from the lack of pr
nvd
CVE-2019-6730HIGHCVSS 8.8≤ 9.3.0.108262019-03-21
CVE-2019-6730 [HIGH] CWE-416 CVE-2019-6730: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the popUpMenu method. The issue results from the lack of validating the existe
nvd
CVE-2019-6727HIGHCVSS 8.8≤ 9.3.0.108262019-03-21
CVE-2019-6727 [HIGH] CWE-416 CVE-2019-6727: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the XFA remerge method. The issue results from the lack of validating the exis
nvd
CVE-2019-6729HIGHCVSS 8.8≤ 9.3.0.108262019-03-21
CVE-2019-6729 [HIGH] CWE-125 CVE-2019-6729: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from the lack of proper validat
nvd
CVE-2019-6735MEDIUMCVSS 6.5≤ 9.3.0.108262019-03-21
CVE-2019-6735 [MEDIUM] CWE-125 CVE-2019-6735: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from the lack of pro
nvd
CVE-2019-6732MEDIUMCVSS 6.5≤ 9.3.0.108262019-03-21
CVE-2019-6732 [MEDIUM] CWE-125 CVE-2019-6732: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the AFParseDateEx method. The issue results fro
nvd
CVE-2019-6728MEDIUMCVSS 6.5≤ 9.3.0.108262019-03-21
CVE-2019-6728 [MEDIUM] CWE-125 CVE-2019-6728: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from the lack of pro
nvd
CVE-2019-6734MEDIUMCVSS 6.5≤ 9.3.0.108262019-03-21
CVE-2019-6734 [MEDIUM] CWE-416 CVE-2019-6734: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the setInterval method. By performing actions i
nvd
CVE-2019-6733MEDIUMCVSS 6.5≤ 9.3.0.108262019-03-21
CVE-2019-6733 [MEDIUM] CWE-125 CVE-2019-6733: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installat This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of PDF files. The issue results from the lack of p
nvd
CVE-2018-3956HIGHCVSS 7.1≤ 9.3.0.108262019-01-30
CVE-2018-3956 [HIGH] CWE-125 CVE-2018-3956: An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attrib An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Software's PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger an out-of-bounds read, which can disclose sensitive memory content and aid in exploitation when coupled with another vulnerability. An attacker needs to t
nvd
CVE-2018-17693HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17693 [HIGH] CWE-125 CVE-2018-17693: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the conversion of HTML files to PDF. The issue results from t
nvd
CVE-2018-17649HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17649 [HIGH] CWE-416 CVE-2018-17649: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the setAttribute method of a TimeField. The issue
nvd
CVE-2018-17673HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17673 [HIGH] CWE-416 CVE-2018-17673: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the subtype property of a Annotation object. The
nvd
CVE-2018-17625HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17625 [HIGH] CWE-416 CVE-2018-17625: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.1.0.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the setInterval() method. The issue results from
nvd
CVE-2018-17632HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17632 [HIGH] CWE-416 CVE-2018-17632: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the resolveNode event. The issue results from the
nvd