CVE-2026-91790
- EPSS 0.13%
- Veröffentlicht 23.09.2026 07:51:28
- Zuletzt bearbeitet 08.10.2026 12:45:41
When rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects whose optional content attributes are malformed. As a result, the program may access an already-freed internal data structure, triggering a crash due ...
CVE-2026-91791
- EPSS 0.14%
- Veröffentlicht 23.09.2026 07:51:25
- Zuletzt bearbeitet 08.10.2026 12:52:52
When processing a specially crafted PDF file, Foxit PDF Editor/Reader may encounter a reentrant execution condition involving JavaScript triggered by page-visibility events. This can cause the application to access a released page-view object while c...
CVE-2026-91792
- EPSS 0.13%
- Veröffentlicht 23.09.2026 07:51:21
- Zuletzt bearbeitet 08.10.2026 13:20:31
When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layout operations through page- and annotation-related JavaScript actions. This can cause the application to access page objects after they have been rele...
CVE-2026-91793
- EPSS 0.13%
- Veröffentlicht 23.09.2026 07:51:16
- Zuletzt bearbeitet 08.10.2026 13:47:43
When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attributes containing malformed font data. During subsequent annotation appearance reconstruction, it accesses an object after it has been...
CVE-2026-91795
- EPSS 0.09%
- Veröffentlicht 23.09.2026 07:51:06
- Zuletzt bearbeitet 08.10.2026 13:48:36
Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files. This could leave an internal pointer in an invalid state, resulting in chained read and write access violations and pote...
CVE-2026-91796
- EPSS 0.12%
- Veröffentlicht 23.09.2026 07:51:02
- Zuletzt bearbeitet 08.10.2026 13:49:03
The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the user's creden...
CVE-2026-91797
- EPSS 0.22%
- Veröffentlicht 23.09.2026 07:50:59
- Zuletzt bearbeitet 08.10.2026 13:49:35
Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to be written to directories outside the expected secure area when the PDF is opened.
CVE-2026-91799
- EPSS 0.13%
- Veröffentlicht 23.09.2026 07:50:56
- Zuletzt bearbeitet 08.10.2026 13:50:42
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of JavaScript array objects. A specially crafted PDF may cause the application to access a released object during array processing, potentially resulting in application crash...
CVE-2026-91805
- EPSS 0.12%
- Veröffentlicht 23.09.2026 07:50:51
- Zuletzt bearbeitet 08.10.2026 12:20:30
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s PDF page-tree handling. A specially crafted PDF can trigger page-structure changes during rendering, causing the application to access released page objects and resulting in memory co...
CVE-2026-91801
- EPSS 0.15%
- Veröffentlicht 23.09.2026 07:50:42
- Zuletzt bearbeitet 08.10.2026 13:55:02
A path traversal vulnerability exists in Foxit PDF Editor/Reader's handling of embedded PDF resources. Insufficient validation of resource file paths may allow files to be written outside their intended locations, potentially enabling arbitrary code ...