Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
foxitsoftware phantompdf vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2021-38568
An issue exists in Foxit Reader and PhantomPDF prior to 10.1.4. It allows memory corruption during conversion of a PDF document to a different document format.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.8
CVSSv3
CVE-2021-38572
An issue exists in Foxit Reader and PhantomPDF prior to 10.1.4. It allows writing to arbitrary files because the extractPages pathname is not validated.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.8
CVSSv3
CVE-2021-38574
An issue exists in Foxit Reader and PhantomPDF prior to 10.1.4. It allows SQL Injection via crafted data at the end of a string.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
7.5
CVSSv3
CVE-2021-38569
An issue exists in Foxit Reader and PhantomPDF prior to 10.1.4. It allows stack consumption via recursive function calls during the handling of XFA forms or link objects.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.1
CVSSv3
CVE-2021-38570
An issue exists in Foxit Reader and PhantomPDF prior to 10.1.4. It allows malicious users to delete arbitrary files (during uninstallation) via a symlink.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
7.8
CVSSv3
CVE-2021-38571
An issue exists in Foxit Reader and PhantomPDF prior to 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and CNVD-C-2021-68502.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.8
CVSSv3
CVE-2021-38573
An issue exists in Foxit Reader and PhantomPDF prior to 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not validated.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.8
CVSSv3
CVE-2021-33793
Foxit Reader prior to 10.1.4 and PhantomPDF prior to 10.1.4 have an out-of-bounds write because the Cross-Reference table is mishandled during Office document conversion.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.1
CVSSv3
CVE-2021-33794
Foxit Reader prior to 10.1.4 and PhantomPDF prior to 10.1.4 allow information disclosure or an application crash after mishandling the Tab key during XFA form interaction.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
7.8
CVSSv3
CVE-2021-33792
Foxit Reader prior to 10.1.4 and PhantomPDF prior to 10.1.4 have an out-of-bounds write via a crafted /Size key in the Trailer dictionary.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48693
CVE-2024-30851
CVE-2024-34460
CVE-2024-2887
local
CVE-2024-27956
remote code execution
CVE-2024-34475
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »