VYPR

PDF Reader

by Foxitsoftware

CVEs (537)

  • CVE-2019-6755HigJun 3, 2019
    risk 0.51cvss 7.8epss 0.03

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.3.10826. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2019-6754HigJun 3, 2019
    risk 0.51cvss 7.8epss 0.05

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.3.10826. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2018-3961HigOct 2, 2018
    risk 0.51cvss 7.8epss 0.02

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Creator property of the this.info object. An attacker needs to trick the user to open the malicious…

  • CVE-2018-3960HigOct 2, 2018
    risk 0.51cvss 7.8epss 0.02

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Producer property of the this.info object. An attacker needs to trick the user to open the malicious…

  • CVE-2018-3959HigOct 2, 2018
    risk 0.51cvss 7.8epss 0.02

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Author property of the this.info object. An attacker needs to trick the user to open the malicious file…

  • CVE-2018-3958HigOct 2, 2018
    risk 0.51cvss 7.8epss 0.03

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Subject property of the this.info object. An attacker needs to trick the user to open the malicious…

  • CVE-2018-3957HigOct 2, 2018
    risk 0.51cvss 7.8epss 0.03

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Keywords property of the this.info object. An attacker needs to trick the user to open the malicious…

  • CVE-2016-4064HigApr 22, 2016
    risk 0.51cvss 7.8epss 0.03

    Use-after-free vulnerability in the XFA forms handling functionality in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via a crafted remerge call.

  • CVE-2018-3956HigJan 30, 2019
    risk 0.50cvss 7.1epss 0.46

    An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Software's PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger an out-of-bounds read, which can disclose sensitive memory content and aid in…

  • CVE-2025-59802HigDec 11, 2025
    risk 0.49cvss 7.5epss 0.00

    Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via OCG. When Optional Content Groups (OCG) are supported, the state property of an OCG is runtime-only and not included in the digital signature computation buffer. An attacker can leverage JavaScript or PDF…

  • CVE-2022-26979HigAug 6, 2022
    risk 0.49cvss 7.5epss 0.01

    Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL.

  • CVE-2022-27944HigAug 6, 2022
    risk 0.49cvss 7.5epss 0.01

    Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow an exportXFAData NULL pointer dereference.

  • CVE-2022-30557HigMay 11, 2022
    risk 0.49cvss 7.5epss 0.04

    Foxit PDF Reader and PDF Editor before 11.2.2 have a Type Confusion issue that causes a crash because of Unsigned32 mishandling during JavaScript execution.

  • CVE-2021-38567HigAug 11, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Foxit PDF Editor before 11.0.1 and PDF Reader before 11.0.1 on macOS. It mishandles missing dictionary entries, leading to a NULL pointer dereference, aka CNVD-C-2021-95204.

  • CVE-2021-38566HigAug 11, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It allows stack consumption during recursive processing of embedded XML nodes.

  • CVE-2021-38565HigAug 11, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It allows writing to arbitrary files via submitForm.

  • CVE-2018-3962HigOct 2, 2018
    risk 0.48cvss 7.3epss 0.03

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the CreationDate property of the this.info object. An attacker needs to trick the user to open the…

  • CVE-2026-3780HigApr 1, 2026
    risk 0.47cvss 7.3epss 0.00

    The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed…

  • CVE-2025-55310HigDec 11, 2025
    risk 0.47cvss 7.3epss 0.00

    An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. An attacker able to alter or replace the static HTML files used by the StartPage feature can cause the application to load malicious or compromised content upon startup.…

  • CVE-2024-12753HigDec 30, 2024
    risk 0.47cvss 7.3epss 0.00

    Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system…

Page 20 of 27