CVE-2021-27265
- EPSS 3.77%
- Veröffentlicht 30.03.2021 15:15:15
- Zuletzt bearbeitet 21.11.2024 05:57:43
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open...
CVE-2020-27860
- EPSS 6.08%
- Veröffentlicht 12.02.2021 00:15:12
- Zuletzt bearbeitet 21.11.2024 05:21:56
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.0.1.35811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious...
CVE-2020-13548
- EPSS 25.71%
- Veröffentlicht 10.02.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:01:28
In Foxit Reader 10.1.0.37527, a specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If th...
CVE-2018-18688
- EPSS 0%
- Veröffentlicht 07.01.2021 18:15:12
- Zuletzt bearbeitet 21.11.2024 03:56:22
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the...
CVE-2018-18689
- EPSS 0.01%
- Veröffentlicht 07.01.2021 18:15:12
- Zuletzt bearbeitet 27.11.2024 20:11:45
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteR...
CVE-2020-35931
- EPSS 0.09%
- Veröffentlicht 31.12.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:28:32
An issue was discovered in Foxit Reader before 10.1.1 (and before 4.1.1 on macOS) and PhantomPDF before 9.7.5 and 10.x before 10.1.1 (and before 4.1.1 on macOS). An attacker can spoof a certified PDF document via an Evil Annotation Attack because the...
CVE-2020-13547
- EPSS 1.02%
- Veröffentlicht 22.12.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:01:28
A type confusion vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger an improper use of an object, resulting in memory corruption and arbitrary code ex...
CVE-2020-13557
- EPSS 14.03%
- Veröffentlicht 22.12.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:29
A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution. An att...
CVE-2020-13560
- EPSS 19.8%
- Veröffentlicht 22.12.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:29
A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution. An att...
CVE-2020-13570
- EPSS 5.3%
- Veröffentlicht 22.12.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:31
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger the reuse of previously free memory which can lead to arbitrary code execution. An attac...