CVE-2022-24954
- EPSS 11.93%
- Veröffentlicht 11.02.2022 02:15:06
- Zuletzt bearbeitet 21.11.2024 06:51:27
Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpan="-2"' and 'draw colSpan="1"' substrings.
CVE-2022-24955
- EPSS 1.05%
- Veröffentlicht 11.02.2022 02:15:06
- Zuletzt bearbeitet 21.11.2024 06:51:27
Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.
CVE-2022-22150
- EPSS 1.8%
- Veröffentlicht 04.02.2022 23:15:12
- Zuletzt bearbeitet 21.11.2024 06:46:15
A memory corruption vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.1.0.52543. A specially-crafted PDF document can trigger an exception which is improperly handled, leaving the engine in an invalid state, whi...
CVE-2021-40420
- EPSS 4.69%
- Veröffentlicht 04.02.2022 23:15:11
- Zuletzt bearbeitet 21.11.2024 06:24:05
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.1.0.52543. A specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An att...
CVE-2021-45980
- EPSS 1.52%
- Veröffentlicht 04.01.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:33:25
Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via getURL in the JavaScript API.
CVE-2021-45978
- EPSS 1.5%
- Veröffentlicht 04.01.2022 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:33:24
Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via xfa.host.gotoURL in the XFA API.
CVE-2021-45979
- EPSS 1.53%
- Veröffentlicht 04.01.2022 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:33:25
Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via app.launchURL in the JavaScript API.
CVE-2021-38563
- EPSS 1.09%
- Veröffentlicht 11.08.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:17:28
An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It mishandles situations in which an array size (derived from a /Size entry) is smaller than the maximum indirect object number, and thus there is an attempted in...
CVE-2021-38567
- EPSS 0.99%
- Veröffentlicht 11.08.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:17:30
An issue was discovered in Foxit PDF Editor before 11.0.1 and PDF Reader before 11.0.1 on macOS. It mishandles missing dictionary entries, leading to a NULL pointer dereference, aka CNVD-C-2021-95204.
CVE-2021-21831
- EPSS 4.55%
- Veröffentlicht 05.08.2021 21:15:10
- Zuletzt bearbeitet 21.11.2024 05:49:03
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.3.37598. A specially crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An att...