CVE-2026-91810
- EPSS 0.11%
- Veröffentlicht 23.09.2026 07:50:02
- Zuletzt bearbeitet 08.10.2026 14:04:13
A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF image masks. Inconsistent image metadata may cause incorrect alpha-channel processing during rendering, resulting in an out-of-bounds read and...
CVE-2026-91811
- EPSS 0.12%
- Veröffentlicht 23.09.2026 07:49:58
- Zuletzt bearbeitet 23.09.2026 17:58:26
A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s PRC parser due to insufficient validation of vertex indices in triangular fan texture meshes. Successful exploitation could result in memory corruption and an applicat...
CVE-2026-91812
- EPSS 0.08%
- Veröffentlicht 23.09.2026 07:49:51
- Zuletzt bearbeitet 08.10.2026 14:02:28
A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows man-in-the-middle attackers to bypass certificate validation and package integrity checks, potentially enabling arbitrary code execution with system privileges.
CVE-2026-91813
- EPSS 0.09%
- Veröffentlicht 23.09.2026 07:49:37
- Zuletzt bearbeitet 08.10.2026 14:01:22
A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replaced between download and high-privilege extraction due to insufficient file locking and integrity validation. This could enable local attackers to execu...
CVE-2026-91815
- EPSS 0.13%
- Veröffentlicht 23.09.2026 07:49:31
- Zuletzt bearbeitet 08.10.2026 14:00:25
Foxit PDF Editor/Reader does not perform sufficient verification of the JPEG2000 image metadata in the PDF file, which leads to out-of-bounds write in the heap buffer during decoding, potentially causing the program to crash and introducing the risk ...
CVE-2026-91814
- EPSS 0.11%
- Veröffentlicht 23.09.2026 07:49:25
- Zuletzt bearbeitet 23.09.2026 17:58:26
A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of incrementally updated PDF documents. Changes to visible document content may not invalidate the existing signature, allowing attackers to alter signed content and po...
CVE-2026-91816
- EPSS 0.12%
- Veröffentlicht 23.09.2026 07:49:18
- Zuletzt bearbeitet 08.10.2026 14:00:00
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations. Reentrant annotation deletion triggered by embedded JavaScript can cause the application to access an annotation object after it has been released, result...
CVE-2026-91817
- EPSS 0.11%
- Veröffentlicht 23.09.2026 07:49:15
- Zuletzt bearbeitet 01.10.2026 20:23:59
A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded PDF JavaScript. Insufficient validation of string-deletion ranges can cause an integer underflow, resulting in an out-of-bounds rea...
CVE-2026-91818
- EPSS 0.12%
- Veröffentlicht 23.09.2026 07:49:11
- Zuletzt bearbeitet 08.10.2026 13:59:31
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, which is subsequently accessed, resulting...
CVE-2026-91789
- EPSS 0.16%
- Veröffentlicht 23.09.2026 07:49:08
- Zuletzt bearbeitet 08.10.2026 12:38:10
Foxit PDF Editor/Reader’s U3D/GIF texture decoding path contained insufficient validation of image dimensions and related size information. Under certain conditions, this could lead to an incorrectly sized memory allocation and a subsequent out-of-bo...