CVE-2018-7407
- EPSS 0.63%
- Veröffentlicht 24.05.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:05
An issue was discovered in Foxit Reader before 9.1 and PhantomPDF before 9.1. This vulnerability allows remote attackers to execute arbitrary code. User interaction is required to exploit this vulnerability in that the target must visit a malicious p...
CVE-2016-8334
- EPSS 13.46%
- Veröffentlicht 06.01.2017 21:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
A large out-of-bounds read on the heap vulnerability in Foxit PDF Reader can potentially be abused for information disclosure. Combined with another vulnerability, it can be used to leak heap memory layout and in bypassing ASLR.
CVE-2016-8879
- EPSS 0.09%
- Veröffentlicht 31.10.2016 10:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
The thumbnail shell extension plugin (FoxitThumbnailHndlr_x86.dll) in Foxit Reader and PhantomPDF before 8.1 on Windows allows remote attackers to cause a denial of service (out-of-bounds write and application crash) via a crafted JPEG2000 image embe...
CVE-2016-8878
- EPSS 0.36%
- Veröffentlicht 31.10.2016 10:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute arbitrary code via a crafted BMP image embedded in the XFA stream in a PDF document, aka "Data f...
CVE-2016-8877
- EPSS 0.53%
- Veröffentlicht 31.10.2016 10:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap buffer overflow (Out-of-Bounds write) vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows allows remote attackers to execute arbitrary code via a crafted JPEG2000 image embedded in a PDF document, aka a "corrupted suffix pattern" ...
CVE-2016-8876
- EPSS 0.36%
- Veröffentlicht 31.10.2016 10:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF image embedded in the XFA stream in a PDF document, aka "Read ...
CVE-2016-8875
- EPSS 0.09%
- Veröffentlicht 31.10.2016 10:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image, aka "Data from Fau...
CVE-2016-8856
- EPSS 0.01%
- Veröffentlicht 31.10.2016 10:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Foxit Reader for Mac 2.1.0.0804 and earlier and Foxit Reader for Linux 2.1.0.0805 and earlier suffered from a vulnerability where weak file permissions could be exploited by attackers to execute arbitrary code. After the installation, Foxit Reader's ...
- EPSS 10.77%
- Veröffentlicht 10.03.2009 20:30:06
- Zuletzt bearbeitet 09.04.2025 00:30:58
Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing dangerous actions defined in a PDF file, which allows remote attackers to execute arbitrary programs and have ...