« Volver al listado

Foxit

Foxit PDF Editor: vulnerabilidades y CVE

Foxit PDF Editor tiene 330 vulnerabilidades publicadas, 91 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE330
Últimos 12 meses91
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-91818Alta (7.8)0.12%—23 sept 2026
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, which is…
CVE-2026-91816Alta (7.8)0.12%—23 sept 2026
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations. Reentrant annotation deletion triggered by embedded JavaScript can cause the application to access an annotation object…
CVE-2026-91815Alta (7.8)0.13%—23 sept 2026
Foxit PDF Editor/Reader does not perform sufficient verification of the JPEG2000 image metadata in the PDF file, which leads to out-of-bounds write in the heap buffer during decoding, potentially causing the program to…
CVE-2026-91814Media (5.3)0.11%—23 sept 2026
A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of incrementally updated PDF documents. Changes to visible document content may not invalidate the existing signature, allowing attackers…
CVE-2026-91813Alta (8.8)0.09%—23 sept 2026
A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replaced between download and high-privilege extraction due to insufficient file locking and integrity validation. This could…
CVE-2026-91812Alta (7.9)0.08%—23 sept 2026
A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows man-in-the-middle attackers to bypass certificate validation and package integrity checks, potentially enabling arbitrary code execution with system…
CVE-2026-91811Alta (7.8)0.12%—23 sept 2026
A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s PRC parser due to insufficient validation of vertex indices in triangular fan texture meshes. Successful exploitation could result in…
CVE-2026-91810Media (6.1)0.11%—23 sept 2026
A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF image masks. Inconsistent image metadata may cause incorrect alpha-channel processing during rendering,…
CVE-2026-91809Alta (7.8)0.12%—23 sept 2026
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF form fields. Improper validation during field-name traversal may cause the application to access a released object, resulting…
CVE-2026-91807Media (6.1)0.11%—23 sept 2026
A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed image soft-mask data. Insufficient validation of the soft-mask data attribute during image parsing may cause an…
CVE-2026-91806Alta (7.8)0.12%—23 sept 2026
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF form fields. Embedded JavaScript may access form-field references after the corresponding fields have been released, resulting in an…
CVE-2026-91805Alta (7.8)0.12%—23 sept 2026
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s PDF page-tree handling. A specially crafted PDF can trigger page-structure changes during rendering, causing the application to access released page…
CVE-2026-91804Alta (7.8)0.12%—23 sept 2026
A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s rendering of Circle annotations with malformed Cloudy appearance streams in specially crafted PDF files. Insufficient validation of the…
CVE-2026-91803Alta (8.8)0.12%—23 sept 2026
A local privilege escalation vulnerability exists in the updater of Foxit PDF Editor/Reader due to unsafe loading of dynamic-link libraries from a user-writable directory during high-privilege operations. A local…
CVE-2026-91802Alta (7.8)0.12%—23 sept 2026
A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s WebP image decoding due to improper handling of bitmap stride and target buffer formats. Successful exploitation could result in an…
CVE-2026-91801Alta (7.8)0.15%—23 sept 2026
A path traversal vulnerability exists in Foxit PDF Editor/Reader's handling of embedded PDF resources. Insufficient validation of resource file paths may allow files to be written outside their intended locations,…
CVE-2026-91800Alta (8.8)0.10%—23 sept 2026
A local privilege escalation vulnerability exists in the installer of Foxit PDF Editor for macOS due to insufficient validation of a user-modifiable configuration value during high-privilege upgrades. A local attacker…
CVE-2026-91799Alta (7.8)0.13%—23 sept 2026
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of JavaScript array objects. A specially crafted PDF may cause the application to access a released object during array processing, potentially…
CVE-2026-91798Alta (8.8)0.10%—23 sept 2026
A local privilege escalation vulnerability exists in the update daemon of Foxit PDF Editor/Reader due to an insecure permission configuration that allows the configuration file to be modified by regular users, which may…
CVE-2026-91797Alta (7.8)0.21%—23 sept 2026
Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to be written to directories outside the expected secure area when the…
CVE-2026-91796Media (6.1)0.12%—23 sept 2026
The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby…
CVE-2026-91795Alta (7.8)0.08%—23 sept 2026
Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files. This could leave an internal pointer in an invalid state, resulting in chained read and…
CVE-2026-91794Alta (7.8)0.16%—23 sept 2026
An out-of-bounds write vulnerability exists in the PDF rendering process of Foxit PDF Editor/Reader due to insufficient consistency and boundary validation when processing malformed color space data, which may cause the…
CVE-2026-91793Alta (7.8)0.13%—23 sept 2026
When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attributes containing malformed font data. During subsequent annotation appearance reconstruction, it…
CVE-2026-91792Alta (7.8)0.13%—23 sept 2026
When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layout operations through page- and annotation-related JavaScript actions. This can cause the application to access page…
CVE-2026-91791Alta (7.8)0.14%—23 sept 2026
When processing a specially crafted PDF file, Foxit PDF Editor/Reader may encounter a reentrant execution condition involving JavaScript triggered by page-visibility events. This can cause the application to access a…
CVE-2026-91790Alta (7.8)0.13%—23 sept 2026
When rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects whose optional content attributes are malformed. As a result, the program may access an already-freed internal data…
CVE-2026-91789Alta (7.8)0.16%—23 sept 2026
Foxit PDF Editor/Reader’s U3D/GIF texture decoding path contained insufficient validation of image dimensions and related size information. Under certain conditions, this could lead to an incorrectly sized memory…
CVE-2026-91788Media (4.7)0.10%—23 sept 2026
When implementing the JavaScript interface, Foxit PDF Editor/Reader did not perform the attribute authorization checks required by the specification. As a result, a trusted malicious PDF could potentially access…
CVE-2026-91817Media (6.1)0.11%—23 sept 2026
A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded PDF JavaScript. Insufficient validation of string-deletion ranges can cause an integer underflow,…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution26
  2. T1059.007 JavaScript9
  3. T1059 Command and Scripting Interpreter7
  4. T1068 Exploitation for Privilege Escalation4
  5. T1499.004 Application or System Exploitation4
  6. T1059.003 Windows Command Shell3

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Foxit