VYPR

PDF Reader and Editor

by Foxitsoftware

CVEs (9)

  • CVE-2024-32488HigApr 15, 2024
    risk 0.51cvss 7.8epss 0.00

    In Foxit PDF Reader and Editor before 2024.1, Local Privilege Escalation could occur during update checks because weak permissions on the update-service folder allow attackers to place crafted DLL files there.

  • CVE-2021-45980HigJan 4, 2022
    risk 0.51cvss 7.8epss 0.02

    Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via getURL in the JavaScript API.

  • CVE-2021-45979HigJan 4, 2022
    risk 0.51cvss 7.8epss 0.02

    Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via app.launchURL in the JavaScript API.

  • CVE-2021-45978HigJan 4, 2022
    risk 0.51cvss 7.8epss 0.01

    Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via xfa.host.gotoURL in the XFA API.

  • CVE-2025-59802HigDec 11, 2025
    risk 0.49cvss 7.5epss 0.00

    Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via OCG. When Optional Content Groups (OCG) are supported, the state property of an OCG is runtime-only and not included in the digital signature computation buffer. An attacker can leverage JavaScript or PDF…

  • CVE-2022-30557HigMay 11, 2022
    risk 0.49cvss 7.5epss 0.04

    Foxit PDF Reader and PDF Editor before 11.2.2 have a Type Confusion issue that causes a crash because of Unsigned32 mishandling during JavaScript execution.

  • CVE-2022-47881MedJan 18, 2023
    risk 0.42cvss 6.5epss 0.01

    Foxit PDF Reader and PDF Editor 11.2.1.53537 and earlier has an Out-of-Bounds Read vulnerability.

  • CVE-2022-25108MedMar 10, 2022
    risk 0.36cvss 5.5epss 0.01

    Foxit PDF Reader and Editor before 11.2.1 and PhantomPDF before 10.1.7 allow a NULL pointer dereference during PDF parsing because the pointer is used without proper validation.

  • CVE-2025-59803MedDec 11, 2025
    risk 0.34cvss 5.3epss 0.00

    Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker can embed triggers (e.g., JavaScript) in a PDF document that execute during the signing process. When a signer reviews the document, the content appears normal. However, once the…