CVE-2025-55307
- EPSS 0.01%
- Veröffentlicht 11.12.2025 00:00:00
- Zuletzt bearbeitet 12.12.2025 15:18:13
An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. Opening a malicious PDF containing a crafted JavaScript call to search.query() with a crafted cDIPath parameter (e.g., "/") may cause an out-of-bounds rea...
CVE-2025-59803
- EPSS 0.02%
- Veröffentlicht 11.12.2025 00:00:00
- Zuletzt bearbeitet 12.12.2025 15:18:13
Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker can embed triggers (e.g., JavaScript) in a PDF document that execute during the signing process. When a signer reviews the document, the content appears no...
CVE-2010-20010
- EPSS 8.54%
- Veröffentlicht 20.08.2025 16:34:48
- Zuletzt bearbeitet 22.08.2025 18:09:17
Foxit PDF Reader before 4.2.0.0928 does not properly bound-check the /Title entry in the PDF Info dictionary. A specially crafted PDF with an overlong Title string can overflow a fixed-size stack buffer, corrupt the Structured Exception Handler (SEH)...
CVE-2011-10030
- EPSS 3.73%
- Veröffentlicht 20.08.2025 15:33:20
- Zuletzt bearbeitet 22.08.2025 18:09:17
Foxit PDF Reader < 4.3.1.0218 exposes a JavaScript API function, createDataObject(), that allows untrusted PDF content to write arbitrary files anywhere on disk. By embedding a malicious PDF that calls this API, an attacker can drop executables or s...
CVE-2024-29072
- EPSS 0.07%
- Veröffentlicht 28.05.2024 14:15:12
- Zuletzt bearbeitet 22.08.2025 16:03:32
A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which ...
CVE-2024-25575
- EPSS 2.74%
- Veröffentlicht 30.04.2024 15:15:52
- Zuletzt bearbeitet 04.11.2025 18:15:52
A type confusion vulnerability vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Lock object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption ...
CVE-2024-25648
- EPSS 2.04%
- Veröffentlicht 30.04.2024 15:15:52
- Zuletzt bearbeitet 04.11.2025 18:15:52
A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a ComboBox widget. A specially crafted JavaScript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corru...
CVE-2023-41257
- EPSS 0.01%
- Veröffentlicht 27.11.2023 16:15:11
- Zuletzt bearbeitet 04.11.2025 20:16:45
A type confusion vulnerability exists in the way Foxit Reader 12.1.2.15356 handles field value properties. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and re...
CVE-2023-38573
- EPSS 0.02%
- Veröffentlicht 27.11.2023 16:15:10
- Zuletzt bearbeitet 04.11.2025 20:16:34
A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles a signature field. A specially crafted Javascript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corrupt...
CVE-2023-39542
- EPSS 0.11%
- Veröffentlicht 27.11.2023 16:15:10
- Zuletzt bearbeitet 04.11.2025 20:16:36
A code execution vulnerability exists in the Javascript saveAs API of Foxit Reader 12.1.3.15356. A specially crafted malformed file can create arbitrary files, which can lead to remote code execution. An attacker needs to trick the user into opening ...