VYPR

PDF Editor/Reader

by Foxitsoftware

CVEs (24)

  • CVE-2026-91810MedSep 23, 2026
    risk 0.40cvss 6.1epss

    A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF image masks. Inconsistent image metadata may cause incorrect alpha-channel processing during rendering, resulting in an out-of-bounds read and application crash.

  • CVE-2026-91796MedSep 23, 2026
    risk 0.40cvss 6.1epss

    The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the user's credentials.

  • CVE-2026-91788MedSep 23, 2026
    risk 0.31cvss 4.7epss

    When implementing the JavaScript interface, Foxit PDF Editor/Reader did not perform the attribute authorization checks required by the specification. As a result, a trusted malicious PDF could potentially access sensitive content from other documents within the same process and…

  • CVE-2026-18622MedAug 13, 2026
    risk 0.31cvss 4.7epss 0.00

    Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual…

Page 2 of 2