Записи foxitsoftware
798 опубликованных записей вендора foxitsoftware.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 3 · 0,4 %
- Pre-auth RCE
- 356
- С записью об исправлении
- 0,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-416 Use After Free302
- CWE-125 Out-of-bounds Read150
- CWE-787 Out-of-bounds Write81
- CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')77
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer25
- CWE-476 NULL Pointer Dereference15
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
798 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
60На этой неделе | CVE-2021-34833Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893.foxit · pdf reader · CWE-416 | Высокая7,8 | — | 95,7 % | 4 авг. 2021 г. |
56В плане | CVE-2020-13557Эксплойта нет | A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527.foxitsoftware · foxit reader · CWE-416 | Высокая8,8 | — | 70,4 % | 22 дек. 2020 г. |
55В плане | CVE-2020-13548Эксплойта нет | In Foxit Reader 10.1.0.37527, a specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code foxitsoftware · foxit reader · CWE-416 | Высокая8,8 | — | 65,8 % | 10 февр. 2021 г. |
54В плане | CVE-2018-9958Готовый эксплойт | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049.foxitsoftware · foxit reader · CWE-416 | Высокая8,8 | — | 62,3 % | 17 мая 2018 г. |
52В плане | CVE-2009-0836Готовый эксплойт | Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing foxitsoftware · reader · CWE-119 | Критическая10,0 | — | 40,9 % | 10 мар. 2009 г. |
49В плане | CVE-2021-34847Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893.foxit · pdf reader · CWE-416 | Высокая7,8 | — | 61,6 % | 4 авг. 2021 г. |
47В плане | CVE-2018-20247Эксплойта нет | In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree foxitsoftware · quick pdf library · CWE-121 | Высокая7,8 | — | 54,5 % | 24 дек. 2018 г. |
45В плане | CVE-2018-9948Готовый эксплойт | This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935.foxitsoftware · foxit reader · CWE-824 | Средняя6,5 | — | 63,1 % | 17 мая 2018 г. |
44В плане | CVE-2018-3924Эксплойта нет | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.5096.foxitsoftware · foxit reader · CWE-416 | Высокая7,8 | — | 44,1 % | 1 авг. 2018 г. |
44В плане | CVE-2008-1104Эксплойта нет | Stack-based buffer overflow in Foxit Reader before 2.3 build 2912 allows user-assisted remote attackers to execute arbitrary code via a craffoxitsoftware · foxit reader · CWE-119 | Критическая9,3 | — | 22,7 % | 21 мая 2008 г. |
43В плане | CVE-2020-14425Proof of concept | Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API.foxitsoftware · foxit reader | Высокая7,8 | — | 41,1 % | 2 нояб. 2020 г. |
43В плане | CVE-2008-0151Proof of concept | Heap-based buffer overflow in Foxit WAC Server 2.1.0.910, 2.0 Build 3503, and earlier allows remote attackers to cause a denial of service (foxitsoftware · wac server · CWE-119 | Критическая10,0 | — | 8,5 % | 8 янв. 2008 г. |
42В плане | CVE-2018-3956Эксплойта нет | An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Software's PDF Reader versfoxitsoftware · phantompdf · CWE-125 | Высокая7,1 | — | 46,0 % | 30 янв. 2019 г. |
42В плане | CVE-2021-34850Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893.foxit · pdf reader · CWE-416 | Высокая7,8 | — | 38,3 % | 4 авг. 2021 г. |
42В плане | CVE-2008-7031Proof of concept | Heap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to cause a denial of servicfoxitsoftware · wac server · CWE-119 | Критическая10,0 | — | 8,3 % | 24 авг. 2009 г. |
42В плане | CVE-2008-7225Эксплойта нет | Heap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to cause a denial of servicfoxitsoftware · wac server · CWE-119 | Критическая10,0 | — | 5,5 % | 14 сент. 2009 г. |
41В плане | CVE-2018-3843Эксплойта нет | An exploitable type confusion vulnerability exists in the way Foxit PDF Reader version 9.0.1.1049 parses files with associated file annotatifoxitsoftware · foxit reader · CWE-704 | Высокая8,8 | — | 21,6 % | 19 апр. 2018 г. |
40В плане | CVE-2018-14442Proof of concept | Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs.foxitsoftware · foxit reader · CWE-416 | Критическая9,8 | — | 4,7 % | 20 июл. 2018 г. |
40В плане | CVE-2018-17609Эксплойта нет | Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) becausfoxitsoftware · phantompdf · CWE-416 | Критическая9,8 | — | 3,2 % | 28 сент. 2018 г. |
40В плане | CVE-2018-17608Эксплойта нет | Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) becausfoxitsoftware · phantompdf · CWE-416 | Критическая9,8 | — | 3,2 % | 28 сент. 2018 г. |
40В плане | CVE-2018-17610Эксплойта нет | Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) becausfoxitsoftware · phantompdf · CWE-416 | Критическая9,8 | — | 3,2 % | 28 сент. 2018 г. |
40В плане | CVE-2018-17607Эксплойта нет | Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) becausfoxitsoftware · phantompdf · CWE-416 | Критическая9,8 | — | 3,2 % | 28 сент. 2018 г. |
40В плане | CVE-2018-17611Эксплойта нет | Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) becausfoxitsoftware · phantompdf · CWE-416 | Критическая9,8 | — | 3,2 % | 28 сент. 2018 г. |
40В плане | CVE-2020-26534Эксплойта нет | An issue was discovered in Foxit Reader and PhantomPDF before 10.1.foxitsoftware · foxit reader · CWE-416 | Критическая9,8 | — | 2,4 % | 2 окт. 2020 г. |
40В плане | CVE-2018-21242Эксплойта нет | An issue was discovered in Foxit PhantomPDF before 8.3.6.foxitsoftware · phantompdf · CWE-200 | Критическая9,8 | — | 2,2 % | 4 июн. 2020 г. |
- CVE-2021-3483360На этой неделе
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893.
ВысокаяCVSS 7,8Эксплойта нетEPSS 96 %foxit · pdf reader4 авг. 2021 г.
- CVE-2020-1355756В плане
A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527.
ВысокаяCVSS 8,8Эксплойта нетEPSS 70 %foxitsoftware · foxit reader22 дек. 2020 г.
- CVE-2020-1354855В плане
In Foxit Reader 10.1.0.37527, a specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code
ВысокаяCVSS 8,8Эксплойта нетEPSS 66 %foxitsoftware · foxit reader10 февр. 2021 г.
- CVE-2018-995854В плане
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049.
ВысокаяCVSS 8,8Готовый эксплойтEPSS 62 %foxitsoftware · foxit reader17 мая 2018 г.
- CVE-2009-083652В плане
Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing
КритическаяCVSS 10,0Готовый эксплойтEPSS 41 %foxitsoftware · reader10 мар. 2009 г.
- CVE-2021-3484749В плане
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893.
ВысокаяCVSS 7,8Эксплойта нетEPSS 62 %foxit · pdf reader4 авг. 2021 г.
- CVE-2018-2024747В плане
In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree
ВысокаяCVSS 7,8Эксплойта нетEPSS 54 %foxitsoftware · quick pdf library24 дек. 2018 г.
- CVE-2018-994845В плане
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935.
СредняяCVSS 6,5Готовый эксплойтEPSS 63 %foxitsoftware · foxit reader17 мая 2018 г.
- CVE-2018-392444В плане
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.5096.
ВысокаяCVSS 7,8Эксплойта нетEPSS 44 %foxitsoftware · foxit reader1 авг. 2018 г.
- CVE-2008-110444В плане
Stack-based buffer overflow in Foxit Reader before 2.3 build 2912 allows user-assisted remote attackers to execute arbitrary code via a craf
КритическаяCVSS 9,3Эксплойта нетEPSS 23 %foxitsoftware · foxit reader21 мая 2008 г.
- CVE-2020-1442543В плане
Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API.
ВысокаяCVSS 7,8Proof of conceptEPSS 41 %foxitsoftware · foxit reader2 нояб. 2020 г.
- CVE-2008-015143В плане
Heap-based buffer overflow in Foxit WAC Server 2.1.0.910, 2.0 Build 3503, and earlier allows remote attackers to cause a denial of service (
КритическаяCVSS 10,0Proof of conceptEPSS 9 %foxitsoftware · wac server8 янв. 2008 г.
- CVE-2018-395642В плане
An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Software's PDF Reader vers
ВысокаяCVSS 7,1Эксплойта нетEPSS 46 %foxitsoftware · phantompdf30 янв. 2019 г.
- CVE-2021-3485042В плане
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893.
ВысокаяCVSS 7,8Эксплойта нетEPSS 38 %foxit · pdf reader4 авг. 2021 г.
- CVE-2008-703142В плане
Heap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to cause a denial of servic
КритическаяCVSS 10,0Proof of conceptEPSS 8 %foxitsoftware · wac server24 авг. 2009 г.
- CVE-2008-722542В плане
Heap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to cause a denial of servic
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %foxitsoftware · wac server14 сент. 2009 г.
- CVE-2018-384341В плане
An exploitable type confusion vulnerability exists in the way Foxit PDF Reader version 9.0.1.1049 parses files with associated file annotati
ВысокаяCVSS 8,8Эксплойта нетEPSS 22 %foxitsoftware · foxit reader19 апр. 2018 г.
- CVE-2018-1444240В плане
Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs.
КритическаяCVSS 9,8Proof of conceptEPSS 5 %foxitsoftware · foxit reader20 июл. 2018 г.
- CVE-2018-1760940В плане
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) becaus
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %foxitsoftware · phantompdf28 сент. 2018 г.
- CVE-2018-1760840В плане
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) becaus
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %foxitsoftware · phantompdf28 сент. 2018 г.
- CVE-2018-1761040В плане
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) becaus
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %foxitsoftware · phantompdf28 сент. 2018 г.
- CVE-2018-1760740В плане
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) becaus
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %foxitsoftware · phantompdf28 сент. 2018 г.
- CVE-2018-1761140В плане
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) becaus
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %foxitsoftware · phantompdf28 сент. 2018 г.
- CVE-2020-2653440В плане
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %foxitsoftware · foxit reader2 окт. 2020 г.
- CVE-2018-2124240В плане
An issue was discovered in Foxit PhantomPDF before 8.3.6.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %foxitsoftware · phantompdf4 июн. 2020 г.