Foxitsoftware Reader vulnerabilities

259 known vulnerabilities affecting foxitsoftware/reader.

Total CVEs
259
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH228MEDIUM13LOW7

Vulnerabilities

Page 7 of 13
CVE-2018-17652HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17652 [HIGH] CWE-416 CVE-2018-17652: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the mandatory property of a TimeField. The issue
nvd
CVE-2018-17697HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17697 [HIGH] CWE-416 CVE-2018-17697: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of templates. The issue results from the lack of val
nvd
CVE-2018-17687HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17687 [HIGH] CWE-416 CVE-2018-17687: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the exportValues property of a radio button.
nvd
CVE-2018-17672HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17672 [HIGH] CWE-416 CVE-2018-17672: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of array indices. The issue results from the lack of
nvd
CVE-2018-17668HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17668 [HIGH] CWE-416 CVE-2018-17668: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the removeAttribute method of a XFA object. The i
nvd
CVE-2018-17646HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17646 [HIGH] CWE-416 CVE-2018-17646: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the fillColor property of a TimeField. The issue
nvd
CVE-2018-17691HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17691 [HIGH] CWE-416 CVE-2018-17691: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the conversion of HTML files to PDF. The issue results from t
nvd
CVE-2018-17667HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17667 [HIGH] CWE-416 CVE-2018-17667: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the print method of a Host object. The issue resu
nvd
CVE-2018-17630HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17630 [HIGH] CWE-416 CVE-2018-17630: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.1.0.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the openPlayer method. The issue results from the
nvd
CVE-2018-17694HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17694 [HIGH] CWE-416 CVE-2018-17694: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the display property of a button. The issue r
nvd
CVE-2018-17647HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17647 [HIGH] CWE-416 CVE-2018-17647: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the boundItem method of a TimeField. The issue re
nvd
CVE-2018-17704HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17704 [HIGH] CWE-416 CVE-2018-17704: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the textColor property of RadioButton objects. Th
nvd
CVE-2018-17677HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17677 [HIGH] CWE-416 CVE-2018-17677: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the mailDoc method of a app object. The issue res
nvd
CVE-2018-17695HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17695 [HIGH] CWE-416 CVE-2018-17695: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the username property of a TextField. The iss
nvd
CVE-2018-17703HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17703 [HIGH] CWE-416 CVE-2018-17703: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the defaultValue property of ComboBox objects. Th
nvd
CVE-2018-17705HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17705 [HIGH] CWE-416 CVE-2018-17705: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the display property of CheckBox objects. The iss
nvd
CVE-2018-17692HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17692 [HIGH] CWE-787 CVE-2018-17692: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the conversion of HTML files to PDF. The issue results from t
nvd
CVE-2018-17651HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17651 [HIGH] CWE-416 CVE-2018-17651: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the getItemState method of a TimeField. The issue
nvd
CVE-2018-17664HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17664 [HIGH] CWE-416 CVE-2018-17664: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the isCompatibleNS method of a XFA object. The is
nvd
CVE-2018-17685HIGHCVSS 8.8≤ 9.2.0.92972019-01-24
CVE-2018-17685 [HIGH] CWE-843 CVE-2018-17685: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of PDF files. The issue results from the lack of pro
nvd