Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
foxitsoftware reader vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2018-17610
Foxit PhantomPDF and Reader prior to 9.3 allow remote malicious users to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This relates to one of five distinct types of Annotation objects.
Foxitsoftware Phantompdf
Foxitsoftware Reader
9.8
CVSSv3
CVE-2018-14442
Foxit Reader prior to 9.2 and PhantomPDF prior to 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs.
Foxitsoftware Phantompdf
Foxitsoftware Foxit Reader
1 Github repository
9.1
CVSSv3
CVE-2021-38564
An issue exists in Foxit PDF Reader prior to 11.0.1 and PDF Editor prior to 11.0.1. It allows an out-of-bounds read via util.scand.
Foxitsoftware Pdf Editor
Foxitsoftware Pdf Reader
9.1
CVSSv3
CVE-2021-38570
An issue exists in Foxit Reader and PhantomPDF prior to 10.1.4. It allows malicious users to delete arbitrary files (during uninstallation) via a symlink.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.1
CVSSv3
CVE-2021-33794
Foxit Reader prior to 10.1.4 and PhantomPDF prior to 10.1.4 allow information disclosure or an application crash after mishandling the Tab key during XFA form interaction.
Foxitsoftware Foxit Reader
Foxitsoftware Phantompdf
9.1
CVSSv3
CVE-2018-18933
The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote malicious users to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Read Access Violation near NU...
Foxitsoftware Foxit Reader 9.3.0.10826
Foxitsoftware U3d 9.3.0.10809
8.8
CVSSv3
CVE-2023-32616
A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles 3D annotations. A specially crafted Javascript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and result in arbitrary code ...
Foxitsoftware Foxit Reader 12.1.2.15356
8.8
CVSSv3
CVE-2023-35985
An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to a failure to properly validate a dangerous extension. A specially crafted malicious file can create files at arbitrary locations, which can lead to arbitrary...
Foxitsoftware Foxit Reader 12.1.3.15356
1 Github repository
8.8
CVSSv3
CVE-2023-40194
An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to mistreatment of whitespace characters. A specially crafted malicious file can create files at arbitrary locations, which can lead to arbitrary code execution...
Foxitsoftware Foxit Reader 12.1.3.15356
8.8
CVSSv3
CVE-2023-38573
A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles a signature field. A specially crafted Javascript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and result in arbitrary co...
Foxitsoftware Foxit Reader 12.1.2.15356
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-6267
XML injection
CVE-2024-37673
CVE-2024-6266
CVE-2024-30078
arbitrary
CVE-2024-36886
CVE-2024-5346
template injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »