CVE-2026-91805
- EPSS 0.12%
- Veröffentlicht 23.09.2026 07:50:51
- Zuletzt bearbeitet 08.10.2026 12:20:30
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s PDF page-tree handling. A specially crafted PDF can trigger page-structure changes during rendering, causing the application to access released page objects and resulting in memory co...
CVE-2026-91800
- EPSS 0.1%
- Veröffentlicht 23.09.2026 07:50:47
- Zuletzt bearbeitet 23.09.2026 17:58:26
A local privilege escalation vulnerability exists in the installer of Foxit PDF Editor for macOS due to insufficient validation of a user-modifiable configuration value during high-privilege upgrades. A local attacker could exploit this issue to exec...
CVE-2026-91801
- EPSS 0.15%
- Veröffentlicht 23.09.2026 07:50:42
- Zuletzt bearbeitet 08.10.2026 13:55:02
A path traversal vulnerability exists in Foxit PDF Editor/Reader's handling of embedded PDF resources. Insufficient validation of resource file paths may allow files to be written outside their intended locations, potentially enabling arbitrary code ...
CVE-2026-91802
- EPSS 0.12%
- Veröffentlicht 23.09.2026 07:50:37
- Zuletzt bearbeitet 08.10.2026 13:56:03
A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s WebP image decoding due to improper handling of bitmap stride and target buffer formats. Successful exploitation could result in an application crash.
CVE-2026-91804
- EPSS 0.12%
- Veröffentlicht 23.09.2026 07:50:34
- Zuletzt bearbeitet 08.10.2026 13:58:38
A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s rendering of Circle annotations with malformed Cloudy appearance streams in specially crafted PDF files. Insufficient validation of the appearance geometry can result ...
CVE-2026-91806
- EPSS 0.12%
- Veröffentlicht 23.09.2026 07:50:29
- Zuletzt bearbeitet 08.10.2026 12:24:50
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF form fields. Embedded JavaScript may access form-field references after the corresponding fields have been released, resulting in an application crash.
CVE-2026-91807
- EPSS 0.11%
- Veröffentlicht 23.09.2026 07:50:24
- Zuletzt bearbeitet 23.09.2026 17:58:26
A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed image soft-mask data. Insufficient validation of the soft-mask data attribute during image parsing may cause an arithmetic underflow, resulting in...
CVE-2026-91798
- EPSS 0.1%
- Veröffentlicht 23.09.2026 07:50:17
- Zuletzt bearbeitet 23.09.2026 17:58:26
A local privilege escalation vulnerability exists in the update daemon of Foxit PDF Editor/Reader due to an insecure permission configuration that allows the configuration file to be modified by regular users, which may lead to arbitrary script execu...
CVE-2026-91803
- EPSS 0.12%
- Veröffentlicht 23.09.2026 07:50:13
- Zuletzt bearbeitet 08.10.2026 14:05:19
A local privilege escalation vulnerability exists in the updater of Foxit PDF Editor/Reader due to unsafe loading of dynamic-link libraries from a user-writable directory during high-privilege operations. A local attacker could exploit this issue to ...
CVE-2026-91808
- EPSS 0.11%
- Veröffentlicht 23.09.2026 07:50:08
- Zuletzt bearbeitet 08.10.2026 13:53:24
A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor Reader’s handling of PDF image objects with inconsistent compression metadata. Insufficient validation during image decoding may result in an undersized buffer and an out-of-bou...