📦 Foxit Reader

by Foxitsoftware

🔍 What is Foxit Reader?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-38574

CRITICAL CVSS 9.8 Aug 11, 2021

This vulnerability allows SQL injection attacks in Foxit Reader and PhantomPDF through crafted data appended to strings. Attackers can execute arbitrary SQL commands, potentially compromising data int...

CVE-2021-38568

CRITICAL CVSS 9.8 Aug 11, 2021

This vulnerability in Foxit Reader and PhantomPDF allows memory corruption when converting PDF documents to other formats, potentially enabling remote code execution. Attackers could exploit this by t...

CVE-2021-38570

CRITICAL CVSS 9.1 Aug 11, 2021

This vulnerability in Foxit Reader and PhantomPDF allows attackers to delete arbitrary files during uninstallation via symbolic link manipulation. It affects users running vulnerable versions of these...

CVE-2021-38572

CRITICAL CVSS 9.8 Aug 11, 2021

This vulnerability in Foxit Reader and PhantomPDF allows attackers to write arbitrary files due to insufficient validation of the extractPages pathname. Attackers can exploit this to potentially execu...

CVE-2020-26534

CRITICAL CVSS 9.8 Oct 2, 2020

This CVE describes a use-after-free vulnerability in Foxit Reader and PhantomPDF's AcroForm JavaScript engine. Attackers can exploit this by crafting malicious PDF files to execute arbitrary code on v...

CVE-2020-26537

CRITICAL CVSS 9.8 Oct 2, 2020

CVE-2020-26537 is a critical memory corruption vulnerability in Foxit Reader and PhantomPDF that allows attackers to execute arbitrary code by exploiting an out-of-bounds write during PDF shading calc...

CVE-2020-26539

CRITICAL CVSS 9.8 Oct 2, 2020

This vulnerability in Foxit Reader and PhantomPDF allows attackers to execute arbitrary code on affected systems by exploiting a use-after-free memory error when processing PDF files with malformed /V...

CVE-2023-41257

HIGH CVSS 8.8 Nov 27, 2023

A type confusion vulnerability in Foxit Reader 12.1.2.15356 allows arbitrary code execution when processing malicious PDF files containing JavaScript. Attackers can exploit this by tricking users into...

CVE-2023-39542

HIGH CVSS 8.8 Nov 27, 2023

This vulnerability in Foxit Reader's JavaScript saveAs API allows arbitrary file creation when a user opens a malicious PDF file or visits a malicious website with the browser plugin enabled. Successf...

CVE-2023-35985

HIGH CVSS 8.8 Nov 27, 2023

This vulnerability in Foxit Reader allows attackers to create arbitrary files on a victim's system through a malicious PDF file or website. When exploited, it can lead to arbitrary code execution. Use...

CVE-2021-33792

HIGH CVSS 7.8 Jul 9, 2021

This vulnerability allows attackers to execute arbitrary code by exploiting an out-of-bounds write vulnerability in Foxit Reader and PhantomPDF when processing PDF files with a crafted /Size key in th...

CVE-2021-21822

HIGH CVSS 8.8 May 10, 2021

A use-after-free vulnerability in Foxit PDF Reader's JavaScript engine allows arbitrary code execution when users open malicious PDF files. This affects Foxit PDF Reader version 10.1.3.37598 users, pa...

CVE-2021-31449

HIGH CVSS 7.8 May 7, 2021

This vulnerability in Foxit Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containing specially crafted U3D objects. The flaw is a double-f...

CVE-2021-31451

HIGH CVSS 7.8 May 7, 2021

This vulnerability in Foxit Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files or visiting malicious web pages. The flaw exists in how Annotati...

CVE-2021-31453

HIGH CVSS 7.8 May 7, 2021

This is a use-after-free vulnerability in Foxit Reader's XFA Forms handling that allows remote code execution. Attackers can exploit it by tricking users into opening malicious PDF files, potentially ...

CVE-2021-31455

HIGH CVSS 7.8 May 7, 2021

This is a use-after-free vulnerability in Foxit Reader's XFA form handling that allows remote code execution when users open malicious PDF files. Attackers can exploit this to execute arbitrary code w...

CVE-2021-27267

HIGH CVSS 7.8 Mar 30, 2021

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containing specially crafted U3D objects. It affects Foxit PhantomPDF users runn...

CVE-2021-27269

HIGH CVSS 7.8 Mar 30, 2021

This vulnerability allows remote attackers to execute arbitrary code on Foxit PhantomPDF installations by tricking users into opening malicious PDF files containing specially crafted U3D objects. The ...

CVE-2021-27271

HIGH CVSS 7.8 Mar 30, 2021

This vulnerability in Foxit PhantomPDF allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containing specially crafted U3D objects. The flaw is an out...

CVE-2021-27261

HIGH CVSS 7.8 Mar 30, 2021

This vulnerability in Foxit PhantomPDF allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containing specially crafted U3D objects. The flaw exists du...