Skip to main content

Vendor/product archive

foxitsoftware / foxit_reader CVEs

Beta · best-effort

372 CVEs tagged to foxitsoftware / foxit_reader22 Critical, 264 High, 75 Medium, 11 Low, 0 Unrated.

CVE-2023-41257

Published Nov 27, 2023

A type confusion vulnerability exists in the way Foxit Reader 12.1.2.15356 handles field value properties. A specially crafted Javascript code inside a malicious PDF document can…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40194

Published Nov 27, 2023

An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to mistreatment of whitespace characters. A specially craft…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39542

Published Nov 27, 2023

A code execution vulnerability exists in the Javascript saveAs API of Foxit Reader 12.1.3.15356. A specially crafted malformed file can create arbitrary files, which can lead to r…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38573

Published Nov 27, 2023

A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles a signature field. A specially crafted Javascript code inside a malicious PDF document can trigg…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-35985

Published Nov 27, 2023

An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to a failure to properly validate a dangerous extension. A…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32616

Published Nov 27, 2023

A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles 3D annotations. A specially crafted Javascript code inside a malicious PDF document can trigger…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43310

Published Nov 9, 2022

An Uncontrolled Search Path Element in Foxit Software released Foxit Reader v11.2.118.51569 allows attackers to escalate privileges when searching for DLL libraries without specif…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21822

Published May 10, 2021

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.3.37598. A specially crafted PDF document can trigger the reuse of prev…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 372 CVEsPage 1 of 15