Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
foxitsoftware foxit reader vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2021-38563
An issue exists in Foxit PDF Reader prior to 11.0.1 and PDF Editor prior to 11.0.1. It mishandles situations in which an array size (derived from a /Size entry) is smaller than the maximum indirect object number, and thus there is an attempted incorrect array access (leading to a...
Foxitsoftware Pdf Editor
Foxit Pdf Reader
9.1
CVSSv3
CVE-2021-38564
An issue exists in Foxit PDF Reader prior to 11.0.1 and PDF Editor prior to 11.0.1. It allows an out-of-bounds read via util.scand.
Foxitsoftware Pdf Editor
Foxitsoftware Pdf Reader
7.5
CVSSv3
CVE-2021-38565
An issue exists in Foxit PDF Reader prior to 11.0.1 and PDF Editor prior to 11.0.1. It allows writing to arbitrary files via submitForm.
Foxitsoftware Pdf Editor
Foxitsoftware Pdf Reader
7.5
CVSSv3
CVE-2021-38566
An issue exists in Foxit PDF Reader prior to 11.0.1 and PDF Editor prior to 11.0.1. It allows stack consumption during recursive processing of embedded XML nodes.
Foxitsoftware Pdf Editor
Foxitsoftware Pdf Reader
7.5
CVSSv3
CVE-2021-38569
An issue exists in Foxit Reader and PhantomPDF prior to 10.1.4. It allows stack consumption via recursive function calls during the handling of XFA forms or link objects.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.1
CVSSv3
CVE-2021-38570
An issue exists in Foxit Reader and PhantomPDF prior to 10.1.4. It allows malicious users to delete arbitrary files (during uninstallation) via a symlink.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.8
CVSSv3
CVE-2021-38572
An issue exists in Foxit Reader and PhantomPDF prior to 10.1.4. It allows writing to arbitrary files because the extractPages pathname is not validated.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.8
CVSSv3
CVE-2021-38573
An issue exists in Foxit Reader and PhantomPDF prior to 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not validated.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.8
CVSSv3
CVE-2021-38574
An issue exists in Foxit Reader and PhantomPDF prior to 10.1.4. It allows SQL Injection via crafted data at the end of a string.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.8
CVSSv3
CVE-2021-33793
Foxit Reader prior to 10.1.4 and PhantomPDF prior to 10.1.4 have an out-of-bounds write because the Cross-Reference table is mishandled during Office document conversion.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »