foxitsoftware records
798 published records for vendor foxitsoftware.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 3 · 0.4%
- Pre-auth RCE
- 356
- With a fix record
- 0.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-416 Use After Free302
- CWE-125 Out-of-bounds Read150
- CWE-787 Out-of-bounds Write81
- CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')77
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer25
- CWE-476 NULL Pointer Dereference15
The weakness classes this vendor ships most often: where to look.
CWEAll records
798 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
60This week | CVE-2021-34833No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893.foxit · pdf reader · CWE-416 | High7.8 | — | 95.7% | Aug 4, 2021 |
56Plan | CVE-2020-13557No exploit | A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527.foxitsoftware · foxit reader · CWE-416 | High8.8 | — | 70.4% | Dec 22, 2020 |
55Plan | CVE-2020-13548No exploit | In Foxit Reader 10.1.0.37527, a specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code foxitsoftware · foxit reader · CWE-416 | High8.8 | — | 65.8% | Feb 10, 2021 |
54Plan | CVE-2018-9958Weaponized | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049.foxitsoftware · foxit reader · CWE-416 | High8.8 | — | 62.3% | May 17, 2018 |
52Plan | CVE-2009-0836Weaponized | Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing foxitsoftware · reader · CWE-119 | Critical10.0 | — | 40.9% | Mar 10, 2009 |
49Plan | CVE-2021-34847No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893.foxit · pdf reader · CWE-416 | High7.8 | — | 61.6% | Aug 4, 2021 |
47Plan | CVE-2018-20247No exploit | In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree foxitsoftware · quick pdf library · CWE-121 | High7.8 | — | 54.5% | Dec 24, 2018 |
45Plan | CVE-2018-9948Weaponized | This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935.foxitsoftware · foxit reader · CWE-824 | Medium6.5 | — | 63.1% | May 17, 2018 |
44Plan | CVE-2018-3924No exploit | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.5096.foxitsoftware · foxit reader · CWE-416 | High7.8 | — | 44.1% | Aug 1, 2018 |
44Plan | CVE-2008-1104No exploit | Stack-based buffer overflow in Foxit Reader before 2.3 build 2912 allows user-assisted remote attackers to execute arbitrary code via a craffoxitsoftware · foxit reader · CWE-119 | Critical9.3 | — | 22.7% | May 21, 2008 |
43Plan | CVE-2020-14425Proof of concept | Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API.foxitsoftware · foxit reader | High7.8 | — | 41.1% | Nov 2, 2020 |
43Plan | CVE-2008-0151Proof of concept | Heap-based buffer overflow in Foxit WAC Server 2.1.0.910, 2.0 Build 3503, and earlier allows remote attackers to cause a denial of service (foxitsoftware · wac server · CWE-119 | Critical10.0 | — | 8.5% | Jan 8, 2008 |
42Plan | CVE-2018-3956No exploit | An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Software's PDF Reader versfoxitsoftware · phantompdf · CWE-125 | High7.1 | — | 46.0% | Jan 30, 2019 |
42Plan | CVE-2021-34850No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893.foxit · pdf reader · CWE-416 | High7.8 | — | 38.3% | Aug 4, 2021 |
42Plan | CVE-2008-7031Proof of concept | Heap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to cause a denial of servicfoxitsoftware · wac server · CWE-119 | Critical10.0 | — | 8.3% | Aug 24, 2009 |
42Plan | CVE-2008-7225No exploit | Heap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to cause a denial of servicfoxitsoftware · wac server · CWE-119 | Critical10.0 | — | 5.5% | Sep 14, 2009 |
41Plan | CVE-2018-3843No exploit | An exploitable type confusion vulnerability exists in the way Foxit PDF Reader version 9.0.1.1049 parses files with associated file annotatifoxitsoftware · foxit reader · CWE-704 | High8.8 | — | 21.6% | Apr 19, 2018 |
40Plan | CVE-2018-14442Proof of concept | Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs.foxitsoftware · foxit reader · CWE-416 | Critical9.8 | — | 4.7% | Jul 20, 2018 |
40Plan | CVE-2018-17609No exploit | Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) becausfoxitsoftware · phantompdf · CWE-416 | Critical9.8 | — | 3.2% | Sep 28, 2018 |
40Plan | CVE-2018-17608No exploit | Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) becausfoxitsoftware · phantompdf · CWE-416 | Critical9.8 | — | 3.2% | Sep 28, 2018 |
40Plan | CVE-2018-17610No exploit | Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) becausfoxitsoftware · phantompdf · CWE-416 | Critical9.8 | — | 3.2% | Sep 28, 2018 |
40Plan | CVE-2018-17607No exploit | Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) becausfoxitsoftware · phantompdf · CWE-416 | Critical9.8 | — | 3.2% | Sep 28, 2018 |
40Plan | CVE-2018-17611No exploit | Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) becausfoxitsoftware · phantompdf · CWE-416 | Critical9.8 | — | 3.2% | Sep 28, 2018 |
40Plan | CVE-2020-26534No exploit | An issue was discovered in Foxit Reader and PhantomPDF before 10.1.foxitsoftware · foxit reader · CWE-416 | Critical9.8 | — | 2.4% | Oct 2, 2020 |
40Plan | CVE-2018-21242No exploit | An issue was discovered in Foxit PhantomPDF before 8.3.6.foxitsoftware · phantompdf · CWE-200 | Critical9.8 | — | 2.2% | Jun 4, 2020 |
- CVE-2021-3483360This week
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893.
HighCVSS 7.8No exploitEPSS 96%foxit · pdf readerAug 4, 2021
- CVE-2020-1355756Plan
A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527.
HighCVSS 8.8No exploitEPSS 70%foxitsoftware · foxit readerDec 22, 2020
- CVE-2020-1354855Plan
In Foxit Reader 10.1.0.37527, a specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code
HighCVSS 8.8No exploitEPSS 66%foxitsoftware · foxit readerFeb 10, 2021
- CVE-2018-995854Plan
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049.
HighCVSS 8.8WeaponizedEPSS 62%foxitsoftware · foxit readerMay 17, 2018
- CVE-2009-083652Plan
Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing
CriticalCVSS 10.0WeaponizedEPSS 41%foxitsoftware · readerMar 10, 2009
- CVE-2021-3484749Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893.
HighCVSS 7.8No exploitEPSS 62%foxit · pdf readerAug 4, 2021
- CVE-2018-2024747Plan
In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree
HighCVSS 7.8No exploitEPSS 54%foxitsoftware · quick pdf libraryDec 24, 2018
- CVE-2018-994845Plan
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935.
MediumCVSS 6.5WeaponizedEPSS 63%foxitsoftware · foxit readerMay 17, 2018
- CVE-2018-392444Plan
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.5096.
HighCVSS 7.8No exploitEPSS 44%foxitsoftware · foxit readerAug 1, 2018
- CVE-2008-110444Plan
Stack-based buffer overflow in Foxit Reader before 2.3 build 2912 allows user-assisted remote attackers to execute arbitrary code via a craf
CriticalCVSS 9.3No exploitEPSS 23%foxitsoftware · foxit readerMay 21, 2008
- CVE-2020-1442543Plan
Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API.
HighCVSS 7.8Proof of conceptEPSS 41%foxitsoftware · foxit readerNov 2, 2020
- CVE-2008-015143Plan
Heap-based buffer overflow in Foxit WAC Server 2.1.0.910, 2.0 Build 3503, and earlier allows remote attackers to cause a denial of service (
CriticalCVSS 10.0Proof of conceptEPSS 9%foxitsoftware · wac serverJan 8, 2008
- CVE-2018-395642Plan
An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Software's PDF Reader vers
HighCVSS 7.1No exploitEPSS 46%foxitsoftware · phantompdfJan 30, 2019
- CVE-2021-3485042Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893.
HighCVSS 7.8No exploitEPSS 38%foxit · pdf readerAug 4, 2021
- CVE-2008-703142Plan
Heap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to cause a denial of servic
CriticalCVSS 10.0Proof of conceptEPSS 8%foxitsoftware · wac serverAug 24, 2009
- CVE-2008-722542Plan
Heap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to cause a denial of servic
CriticalCVSS 10.0No exploitEPSS 5%foxitsoftware · wac serverSep 14, 2009
- CVE-2018-384341Plan
An exploitable type confusion vulnerability exists in the way Foxit PDF Reader version 9.0.1.1049 parses files with associated file annotati
HighCVSS 8.8No exploitEPSS 22%foxitsoftware · foxit readerApr 19, 2018
- CVE-2018-1444240Plan
Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs.
CriticalCVSS 9.8Proof of conceptEPSS 5%foxitsoftware · foxit readerJul 20, 2018
- CVE-2018-1760940Plan
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) becaus
CriticalCVSS 9.8No exploitEPSS 3%foxitsoftware · phantompdfSep 28, 2018
- CVE-2018-1760840Plan
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) becaus
CriticalCVSS 9.8No exploitEPSS 3%foxitsoftware · phantompdfSep 28, 2018
- CVE-2018-1761040Plan
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) becaus
CriticalCVSS 9.8No exploitEPSS 3%foxitsoftware · phantompdfSep 28, 2018
- CVE-2018-1760740Plan
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) becaus
CriticalCVSS 9.8No exploitEPSS 3%foxitsoftware · phantompdfSep 28, 2018
- CVE-2018-1761140Plan
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) becaus
CriticalCVSS 9.8No exploitEPSS 3%foxitsoftware · phantompdfSep 28, 2018
- CVE-2020-2653440Plan
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.
CriticalCVSS 9.8No exploitEPSS 2%foxitsoftware · foxit readerOct 2, 2020
- CVE-2018-2124240Plan
An issue was discovered in Foxit PhantomPDF before 8.3.6.
CriticalCVSS 9.8No exploitEPSS 2%foxitsoftware · phantompdfJun 4, 2020