📦 Pdf Reader

by Foxit

🔍 What is Pdf Reader?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-24955

CRITICAL CVSS 9.8 Feb 11, 2022

CVE-2022-24955 is a DLL hijacking vulnerability in Foxit PDF software that allows attackers to execute arbitrary code by placing malicious DLL files in directories searched by the application. This af...

CVE-2021-38563

CRITICAL CVSS 9.8 Aug 11, 2021

This vulnerability in Foxit PDF software allows attackers to trigger memory corruption through malformed PDF files, potentially leading to remote code execution. It affects all users of Foxit PDF Read...

CVE-2025-66499

HIGH CVSS 7.8 Dec 19, 2025

A heap-based buffer overflow vulnerability in Foxit PDF Reader's JBIG2 image parsing allows remote code execution when opening malicious PDF files. This affects all users of vulnerable Foxit PDF Reade...

CVE-2025-66494

HIGH CVSS 7.8 Dec 19, 2025

A use-after-free vulnerability in Foxit PDF Reader's PDF parsing allows remote code execution when opening malicious PDF files. This affects Windows users running vulnerable versions of Foxit PDF Read...

CVE-2025-66495

HIGH CVSS 7.8 Dec 19, 2025

A use-after-free vulnerability in Foxit PDF Reader's annotation handling allows remote code execution when opening malicious PDF files containing crafted JavaScript. This affects Windows and MacOS use...

CVE-2025-66493

HIGH CVSS 7.8 Dec 19, 2025

A use-after-free vulnerability in Foxit PDF software allows remote code execution when opening malicious PDF files containing crafted JavaScript. This affects Foxit PDF Reader and Foxit PDF Editor use...

CVE-2025-13941

HIGH CVSS 8.8 Dec 19, 2025

A local privilege escalation vulnerability in Foxit PDF Reader/Editor Update Service allows low-privileged local attackers to modify plugin installation resources. When the service executes these reso...

CVE-2025-59802

HIGH CVSS 7.5 Dec 11, 2025

This vulnerability in Foxit PDF Editor and Reader allows attackers to modify the visual content of digitally signed PDFs without invalidating the signature. By exploiting Optional Content Groups (OCG)...

CVE-2025-55310

HIGH CVSS 7.3 Dec 11, 2025

This vulnerability allows attackers who can modify or replace static HTML files used by Foxit PDF's StartPage feature to inject malicious content that loads automatically when the application starts. ...

CVE-2025-55312

HIGH CVSS 7.8 Dec 11, 2025

A memory corruption vulnerability in Foxit PDF and Editor allows attackers to execute arbitrary code by exploiting improper state updates when deleting PDF pages via JavaScript. This affects Windows u...

CVE-2025-55313

HIGH CVSS 7.8 Dec 11, 2025

This vulnerability in Foxit PDF software allows arbitrary code execution when processing malicious PDF files. Attackers can exploit memory corruption by manipulating form field properties via JavaScri...

CVE-2025-55314

HIGH CVSS 7.8 Dec 11, 2025

This vulnerability in Foxit PDF software allows memory corruption when pages are deleted via JavaScript, potentially enabling arbitrary code execution. It affects Windows and macOS users running Foxit...

CVE-2025-9326

HIGH CVSS 7.8 Sep 2, 2025

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PRC files. The flaw exists in PRC file parsing where improper data val...

CVE-2025-9328

HIGH CVSS 7.8 Sep 2, 2025

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PRC files. The flaw exists in PRC file parsing where improper data val...

CVE-2025-9330

HIGH CVSS 7.8 Sep 2, 2025

This vulnerability in Foxit PDF Reader's Update Service allows local attackers to escalate privileges by loading a malicious library from an unsecured location. Attackers who already have low-privileg...

CVE-2025-32451

HIGH CVSS 8.8 Aug 13, 2025

A memory corruption vulnerability in Foxit Reader allows arbitrary code execution when users open malicious PDF files containing specially crafted JavaScript. Attackers can exploit this by tricking us...

CVE-2024-12751

HIGH CVSS 7.8 Dec 30, 2024

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containing specially crafted AcroForms. The flaw is an out-o...

CVE-2024-12753

HIGH CVSS 7.3 Dec 30, 2024

This vulnerability in Foxit PDF Reader allows local attackers to escalate privileges from low-privileged user accounts to SYSTEM level by exploiting a flaw in the installer through junction manipulati...

CVE-2024-47810

HIGH CVSS 8.8 Dec 18, 2024

A use-after-free vulnerability in Foxit Reader 2024.3.0.26795 allows arbitrary code execution when processing malicious PDF files containing specially crafted JavaScript with 3D page objects. Attacker...

CVE-2024-9251

HIGH CVSS 7.8 Nov 22, 2024

This CVE describes a use-after-free vulnerability in Foxit PDF Reader's annotation handling that allows information disclosure. Attackers can exploit it by tricking users into opening malicious PDF fi...

CVE-2024-9253

HIGH CVSS 7.1 Nov 22, 2024

This vulnerability in Foxit PDF Reader allows remote attackers to read memory beyond allocated buffers when processing malicious PDF files with AcroForms. It can disclose sensitive information and pot...

CVE-2024-9255

HIGH CVSS 7.8 Nov 22, 2024

This is a use-after-free vulnerability in Foxit PDF Reader's annotation handling that allows remote attackers to execute arbitrary code when users open malicious PDF files. Attackers can exploit this ...

CVE-2024-9244

HIGH CVSS 7.8 Nov 22, 2024

This vulnerability in Foxit PDF Reader's Update Service allows local attackers to escalate privileges from a low-privileged user to SYSTEM by exploiting incorrect permissions on configuration files. I...

CVE-2024-9246

HIGH CVSS 7.1 Nov 22, 2024

This vulnerability in Foxit PDF Reader allows attackers to read memory beyond allocated buffers when processing malicious PDF files with specially crafted annotations. It can disclose sensitive inform...

CVE-2024-9248

HIGH CVSS 7.8 Nov 22, 2024

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw exists in PDF parsing where improper data validati...

CVE-2024-9249

HIGH CVSS 7.1 Nov 22, 2024

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw exists in PDF parsing where improper data validati...

CVE-2024-7725

HIGH CVSS 8.8 Aug 21, 2024

This is a use-after-free vulnerability in Foxit PDF Reader's AcroForm handling that allows remote attackers to execute arbitrary code when a user opens a malicious PDF file. It affects users of vulner...

CVE-2024-7723

HIGH CVSS 8.8 Aug 21, 2024

This is a use-after-free vulnerability in Foxit PDF Reader's AcroForm handling that allows remote code execution when users open malicious PDF files. Attackers can exploit this to run arbitrary code w...

CVE-2021-34971

HIGH CVSS 7.8 May 7, 2024

This vulnerability allows remote attackers to execute arbitrary code on affected Foxit PDF Reader installations by tricking users into opening malicious PDF files containing specially crafted JPG2000 ...

CVE-2021-34974

HIGH CVSS 7.8 May 7, 2024

This is a use-after-free vulnerability in Foxit PDF Reader's annotation handling that allows remote attackers to execute arbitrary code when a user opens a malicious PDF file. It affects Foxit PDF Rea...

CVE-2021-34966

HIGH CVSS 7.8 May 7, 2024

This is a use-after-free vulnerability in Foxit PDF Editor's handling of FileAttachment annotations that allows remote code execution. Attackers can exploit it by tricking users into opening malicious...

CVE-2021-34968

HIGH CVSS 7.8 May 7, 2024

This is a use-after-free vulnerability in Foxit PDF Editor's transitionToState method that allows remote attackers to execute arbitrary code. Attackers can exploit it by tricking users into opening ma...

CVE-2021-34960

HIGH CVSS 7.8 May 7, 2024

This is a use-after-free vulnerability in Foxit PDF Editor's handling of Circle Annotation objects, allowing remote attackers to execute arbitrary code when a user opens a malicious PDF file or visits...

CVE-2021-34962

HIGH CVSS 7.8 May 7, 2024

This is a use-after-free vulnerability in Foxit PDF Editor's handling of Caret Annotation objects that allows remote code execution. Attackers can exploit it by tricking users into opening malicious P...

CVE-2021-34964

HIGH CVSS 7.8 May 7, 2024

This is a use-after-free vulnerability in Foxit PDF Editor's polygon annotation handling that allows remote code execution when users open malicious PDF files. Attackers can exploit this to run arbitr...

CVE-2021-34954

HIGH CVSS 7.8 May 7, 2024

This is a use-after-free vulnerability in Foxit PDF Editor's handling of StrikeOut annotations that allows remote code execution. Attackers can exploit it by tricking users into opening malicious PDF ...

CVE-2021-34956

HIGH CVSS 7.8 May 7, 2024

This is a use-after-free vulnerability in Foxit PDF Editor's underline annotation handling that allows remote attackers to execute arbitrary code. Users who open malicious PDF files or visit malicious...

CVE-2021-34958

HIGH CVSS 7.8 May 7, 2024

This is a use-after-free vulnerability in Foxit PDF Editor's text annotation handling that allows remote attackers to execute arbitrary code when a user opens a malicious PDF file. Attackers can explo...

CVE-2021-34950

HIGH CVSS 7.8 May 7, 2024

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw exists in how Annotation objects are handled, enab...

CVE-2021-34952

HIGH CVSS 7.8 May 7, 2024

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by exploiting a use-after-free flaw in Annotation object handling. It affects users who open malicious PDF file...

CVE-2023-51556

HIGH CVSS 7.8 May 3, 2024

This vulnerability in Foxit PDF Reader allows attackers to execute arbitrary code by tricking users into opening malicious PDF files. It affects users running vulnerable versions of Foxit PDF Reader w...

CVE-2023-51560

HIGH CVSS 7.8 May 3, 2024

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw exists in how the software handles annotation obje...

CVE-2025-66496

MEDIUM CVSS 5.3 Dec 19, 2025

A memory corruption vulnerability in Foxit PDF Reader's 3D annotation handling allows attackers to cause out-of-bounds memory access via specially crafted PRC content in PDF files. This could lead to ...

CVE-2025-66497

MEDIUM CVSS 5.3 Dec 19, 2025

A memory corruption vulnerability in Foxit PDF Reader allows attackers to execute arbitrary code by tricking users into opening malicious PDF files containing specially crafted PRC content. This affec...

CVE-2025-66498

MEDIUM CVSS 5.3 Dec 19, 2025

A memory corruption vulnerability in Foxit PDF Reader's 3D annotation handling allows attackers to execute arbitrary code or cause denial of service by tricking users into opening malicious PDF files....

CVE-2025-59803

MEDIUM CVSS 5.3 Dec 11, 2025

Foxit PDF Editor and Reader versions before 2025.2.1 contain a signature spoofing vulnerability where attackers can embed triggers (like JavaScript) in PDF documents. These triggers execute during the...

CVE-2025-55308

MEDIUM CVSS 6.7 Dec 11, 2025

A use-after-free vulnerability in Foxit PDF and Editor for Windows allows memory corruption when opening a malicious PDF containing JavaScript that calls closeDoc() prematurely. This could lead to inf...

CVE-2025-55309

MEDIUM CVSS 6.7 Dec 11, 2025

A use-after-free vulnerability in Foxit PDF and Editor allows memory corruption or crashes when processing malicious PDF files containing specific JavaScript. Attackers could exploit this by tricking ...

CVE-2025-55311

MEDIUM CVSS 6.5 Dec 11, 2025

This vulnerability in Foxit PDF software allows attackers to create malicious PDFs that use JavaScript to modify annotation content and clear modification status, bypassing digital signature verificat...

CVE-2025-9323

MEDIUM CVSS 5.5 Sep 2, 2025

This vulnerability in Foxit PDF Reader allows remote attackers to disclose sensitive information by tricking users into opening malicious JP2 files. The flaw exists in JP2 file parsing where improper ...

CVE-2025-9324

MEDIUM CVSS 5.5 Sep 2, 2025

Foxit PDF Reader contains an out-of-bounds read vulnerability when parsing PRC files, allowing attackers to disclose sensitive information from affected systems. This affects users who open malicious ...

CVE-2025-9325

MEDIUM CVSS 5.5 Sep 2, 2025

This vulnerability in Foxit PDF Reader allows attackers to read memory beyond allocated bounds when parsing malicious PRC files, potentially disclosing sensitive information. Users who open malicious ...

CVE-2024-7722

MEDIUM CVSS 4.3 Aug 21, 2024

A use-after-free vulnerability in Foxit PDF Reader's Doc object handling allows remote attackers to disclose sensitive information. Attackers can exploit this by tricking users into opening malicious ...

CVE-2021-34976

MEDIUM CVSS 5.5 May 7, 2024

CVE-2021-34976 is a use-after-free vulnerability in Foxit PDF Reader's PDF file parsing that allows remote attackers to disclose sensitive information. Users who open malicious PDF files or visit mali...

CVE-2021-34973

MEDIUM CVSS 5.5 May 7, 2024

CVE-2021-34973 is a use-after-free vulnerability in Foxit PDF Reader's PDF file parsing that allows attackers to disclose sensitive information. Users who open malicious PDF files or visit malicious w...

CVE-2021-34970

MEDIUM CVSS 5.5 May 7, 2024

This is a format string vulnerability in Foxit PDF Reader's print method that allows information disclosure. Attackers can exploit it by tricking users into opening malicious PDF files or visiting mal...

CVE-2021-34949

MEDIUM CVSS 5.5 May 7, 2024

This vulnerability in Foxit PDF Reader allows attackers to read sensitive information from memory by tricking users into opening malicious PDF files. The flaw exists in how annotation objects are proc...

CVE-2022-43640

MEDIUM CVSS 5.5 Mar 29, 2023

CVE-2022-43640 is an out-of-bounds read vulnerability in Foxit PDF Reader that allows attackers to disclose sensitive information from affected systems. Users who open malicious PDF files or visit mal...

CVE-2022-37383

MEDIUM CVSS 5.5 Mar 29, 2023

This vulnerability in Foxit PDF Reader allows remote attackers to read sensitive information from memory by exploiting a JavaScript flaw in Doc object handling. Users who open malicious PDF files or v...

CVE-2022-37386

MEDIUM CVSS 5.5 Mar 29, 2023

This vulnerability in Foxit PDF Reader allows remote attackers to read sensitive information from memory by exploiting an out-of-bounds read in the resetForm method. Attackers can combine this with ot...

CVE-2022-37379

MEDIUM CVSS 5.5 Mar 29, 2023

This vulnerability in Foxit PDF Reader allows remote attackers to disclose sensitive information by exploiting improper object validation in the AFSpecial_KeystrokeEx method. Users who open malicious ...

CVE-2025-55307

LOW CVSS 3.3 Dec 11, 2025

This vulnerability in Foxit PDF software allows attackers to trigger an out-of-bounds read by tricking users into opening malicious PDF files containing crafted JavaScript. The flaw could lead to info...