CVE-2020-17417
- EPSS 3.07%
- Published 13.10.2020 17:15:14
- Last modified 21.11.2024 05:08:03
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.0.1.35811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious...
CVE-2020-17410
- EPSS 1.96%
- Published 13.10.2020 17:15:13
- Last modified 21.11.2024 05:08:02
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.0.0.35798. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malic...
CVE-2020-26534
- EPSS 0.03%
- Published 02.10.2020 08:15:12
- Last modified 21.11.2024 05:20:01
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Field::ClearItems and Field::DeleteOptions, during AcroForm JavaScript execution.
CVE-2020-26535
- EPSS 0.02%
- Published 02.10.2020 08:15:12
- Last modified 21.11.2024 05:20:01
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. If TslAlloc attempts to allocate thread local storage but obtains an unacceptable index value, V8 throws an exception that leads to a write access violation (and read access violatio...
CVE-2020-26536
- EPSS 0.04%
- Published 02.10.2020 08:15:12
- Last modified 21.11.2024 05:20:01
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is a NULL pointer dereference via a crafted PDF document.
CVE-2020-26537
- EPSS 0.03%
- Published 02.10.2020 08:15:12
- Last modified 21.11.2024 05:20:01
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. In a certain Shading calculation, the number of outputs is unequal to the number of color components in a color space. This causes an out-of-bounds write.
CVE-2020-26538
- EPSS 0.01%
- Published 02.10.2020 08:15:12
- Last modified 21.11.2024 05:20:02
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. It allows attackers to execute arbitrary code via a Trojan horse taskkill.exe in the current working directory.
CVE-2020-26539
- EPSS 2.83%
- Published 02.10.2020 08:15:12
- Last modified 21.11.2024 05:20:02
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. When there is a multiple interpretation error for /V (in the Additional Action and Field dictionaries), a use-after-free can occur with resultant remote code execution (or an informa...
CVE-2020-26540
- EPSS 0.01%
- Published 02.10.2020 08:15:12
- Last modified 21.11.2024 05:20:02
An issue was discovered in Foxit Reader and PhantomPDF before 4.1 on macOS. Because the Hardened Runtime protection mechanism is not applied to code signing, code injection (or an information leak) can occur.
CVE-2020-11493
- EPSS 0.08%
- Published 04.09.2020 04:15:11
- Last modified 21.11.2024 04:58:00
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to Stream without concern for a crafted XObject.