VYPR

PDF

by Foxitsoftware

CVEs (15)

  • CVE-2017-8059HigMay 5, 2017
    risk 0.53cvss 8.1epss 0.01

    Acceptance of invalid/self-signed TLS certificates in "Foxit PDF - PDF reader, editor, form, signature" before 5.4 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept login information (username/password), in addition to the static…

  • CVE-2025-55314HigDec 11, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume these states…

  • CVE-2025-55313HigDec 11, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. They allow potential arbitrary code execution when processing crafted PDF files. The vulnerability stems from insufficient handling of memory allocation failures after…

  • CVE-2025-55312HigDec 11, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume these states are valid,…

  • CVE-2025-55310HigDec 11, 2025
    risk 0.47cvss 7.3epss 0.00

    An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. An attacker able to alter or replace the static HTML files used by the StartPage feature can cause the application to load malicious or compromised content upon startup.…

  • CVE-2025-55309MedDec 11, 2025
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can contain JavaScript that attaches an OnBlur action on a form field that destroys an annotation. During user right-click interaction, the program's internal…

  • CVE-2025-55311MedDec 11, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can use JavaScript to alter annotation content and subsequently clear the file's modification status via JavaScript interfaces. This circumvents digital…

  • CVE-2026-3778MedApr 1, 2026
    risk 0.40cvss 6.2epss 0.00

    The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pages and annotations are crafted that reference each other in a loop, passing the document to APIs (e.g., SOAP) that perform deep traversal can cause…

  • CVE-2018-18689MedJan 7, 2021
    risk 0.35cvss 5.3epss 0.04

    The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations…

  • CVE-2018-18688MedJan 7, 2021
    risk 0.35cvss 5.3epss 0.01

    The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature…

  • CVE-2026-3774MedApr 1, 2026
    risk 0.31cvss 4.7epss 0.00

    The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, annotations, or optional content groups (OCGs) immediately before or after redaction, encryption, or printing. These script‑driven updates are not fully covered…

  • CVE-2025-55307LowDec 11, 2025
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. Opening a malicious PDF containing a crafted JavaScript call to search.query() with a crafted cDIPath parameter (e.g., "/") may cause an out-of-bounds read in internal path-parsing…

  • CVE-2026-57254HigJul 8, 2026
    risk 0.00cvss 7.8epss 0.00

    There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF, it fails to perform proper type checking, ultimately causing the application to crash.

  • CVE-2026-13128HigJul 8, 2026
    risk 0.00cvss 7.8epss 0.00

    Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the relevant properties of the document view, eventually leading to the crash of the application.

  • CVE-2026-13126HigJul 8, 2026
    risk 0.00cvss 7.8epss 0.00

    The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invalid pop-up annotations, resulting in the program crashing.