Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
foxitsoftware phantompdf vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2021-38573
An issue exists in Foxit Reader and PhantomPDF prior to 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not validated.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.8
CVSSv3
CVE-2021-38574
An issue exists in Foxit Reader and PhantomPDF prior to 10.1.4. It allows SQL Injection via crafted data at the end of a string.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.8
CVSSv3
CVE-2021-38568
An issue exists in Foxit Reader and PhantomPDF prior to 10.1.4. It allows memory corruption during conversion of a PDF document to a different document format.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
7.5
CVSSv3
CVE-2021-38569
An issue exists in Foxit Reader and PhantomPDF prior to 10.1.4. It allows stack consumption via recursive function calls during the handling of XFA forms or link objects.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.1
CVSSv3
CVE-2021-38570
An issue exists in Foxit Reader and PhantomPDF prior to 10.1.4. It allows malicious users to delete arbitrary files (during uninstallation) via a symlink.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
7.8
CVSSv3
CVE-2021-38571
An issue exists in Foxit Reader and PhantomPDF prior to 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and CNVD-C-2021-68502.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.8
CVSSv3
CVE-2021-38572
An issue exists in Foxit Reader and PhantomPDF prior to 10.1.4. It allows writing to arbitrary files because the extractPages pathname is not validated.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.8
CVSSv3
CVE-2021-33793
Foxit Reader prior to 10.1.4 and PhantomPDF prior to 10.1.4 have an out-of-bounds write because the Cross-Reference table is mishandled during Office document conversion.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.1
CVSSv3
CVE-2021-33794
Foxit Reader prior to 10.1.4 and PhantomPDF prior to 10.1.4 allow information disclosure or an application crash after mishandling the Tab key during XFA form interaction.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
7.8
CVSSv3
CVE-2021-33792
Foxit Reader prior to 10.1.4 and PhantomPDF prior to 10.1.4 have an out-of-bounds write via a crafted /Size key in the Trailer dictionary.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »