CVE-2023-32616
- EPSS 0.02%
- Veröffentlicht 27.11.2023 16:15:08
- Zuletzt bearbeitet 21.11.2024 08:03:42
A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles 3D annotations. A specially crafted Javascript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption...
CVE-2022-43310
- EPSS 0.01%
- Veröffentlicht 09.11.2022 21:15:17
- Zuletzt bearbeitet 01.05.2025 16:15:24
An Uncontrolled Search Path Element in Foxit Software released Foxit Reader v11.2.118.51569 allows attackers to escalate privileges when searching for DLL libraries without specifying an absolute path.
CVE-2021-38574
- EPSS 0.02%
- Veröffentlicht 11.08.2021 22:15:09
- Zuletzt bearbeitet 21.11.2024 06:17:32
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.
CVE-2021-38568
- EPSS 0.03%
- Veröffentlicht 11.08.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:17:30
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows memory corruption during conversion of a PDF document to a different document format.
CVE-2021-38569
- EPSS 0.02%
- Veröffentlicht 11.08.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:17:30
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows stack consumption via recursive function calls during the handling of XFA forms or link objects.
CVE-2021-38570
- EPSS 0.04%
- Veröffentlicht 11.08.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:17:31
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows attackers to delete arbitrary files (during uninstallation) via a symlink.
CVE-2021-38571
- EPSS 0.03%
- Veröffentlicht 11.08.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:17:31
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and CNVD-C-2021-68502.
CVE-2021-38572
- EPSS 0.02%
- Veröffentlicht 11.08.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:17:31
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because the extractPages pathname is not validated.
CVE-2021-38573
- EPSS 0.02%
- Veröffentlicht 11.08.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:17:32
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not validated.
CVE-2021-33793
- EPSS 0.03%
- Veröffentlicht 11.08.2021 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:09:35
Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write because the Cross-Reference table is mishandled during Office document conversion.