Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
foxit phantompdf vulnerabilities and exploits
(subscribe to this query)
7.8
CVSSv3
CVE-2020-26538
An issue exists in Foxit Reader and PhantomPDF prior to 10.1. It allows malicious users to execute arbitrary code via a Trojan horse taskkill.exe in the current working directory.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
7.8
CVSSv3
CVE-2021-33792
Foxit Reader prior to 10.1.4 and PhantomPDF prior to 10.1.4 have an out-of-bounds write via a crafted /Size key in the Trailer dictionary.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.8
CVSSv3
CVE-2021-33793
Foxit Reader prior to 10.1.4 and PhantomPDF prior to 10.1.4 have an out-of-bounds write because the Cross-Reference table is mishandled during Office document conversion.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.1
CVSSv3
CVE-2021-33794
Foxit Reader prior to 10.1.4 and PhantomPDF prior to 10.1.4 allow information disclosure or an application crash after mishandling the Tab key during XFA form interaction.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
8.8
CVSSv3
CVE-2017-8454
Foxit Reader prior to 8.2.1 and PhantomPDF prior to 8.2.1 have an out-of-bounds read that allows remote malicious users to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.8
CVSSv3
CVE-2018-14442
Foxit Reader prior to 9.2 and PhantomPDF prior to 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs.
Foxitsoftware Phantompdf
Foxitsoftware Foxit Reader
1 Github repository
9.8
CVSSv3
CVE-2020-26535
An issue exists in Foxit Reader and PhantomPDF prior to 10.1. If TslAlloc attempts to allocate thread local storage but obtains an unacceptable index value, V8 throws an exception that leads to a write access violation (and read access violation).
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.8
CVSSv3
CVE-2020-26539
An issue exists in Foxit Reader and PhantomPDF prior to 10.1. When there is a multiple interpretation error for /V (in the Additional Action and Field dictionaries), a use-after-free can occur with resultant remote code execution (or an information leak).
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
5.5
CVSSv3
CVE-2021-33795
Foxit Reader prior to 10.1.4 and PhantomPDF prior to 10.1.4 produce incorrect PDF document signatures because the certificate name, document owner, and signature author are mishandled.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
7.8
CVSSv3
CVE-2016-4059
Use-after-free vulnerability in Foxit Reader and PhantomPDF prior to 7.3.4 on Windows allows remote malicious users to execute arbitrary code via a crafted FlateDecode stream in a PDF document.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »