Foxitsoftware
Foxitsoftware Reader: vulnerabilidades y CVE
Foxitsoftware Reader tiene 259 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 10 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE259
Últimos 12 meses0
Críticas10
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-31473 | Alta (7.8) | 7.7% | — | 21 may 2021 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.3.37598. User interaction is required to exploit this vulnerability in that the target must visit a… |
| CVE-2021-31461 | Alta (7.8) | 4.3% | — | 7 may 2021 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a… |
| CVE-2021-31460 | Alta (7.8) | 2.8% | — | 7 may 2021 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a… |
| CVE-2021-31459 | Alta (7.8) | 2.8% | — | 7 may 2021 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a… |
| CVE-2021-31458 | Alta (7.8) | 2.8% | — | 7 may 2021 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a… |
| CVE-2021-31457 | Alta (7.8) | 2.8% | — | 7 may 2021 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a… |
| CVE-2021-31456 | Alta (7.8) | 2.8% | — | 7 may 2021 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a… |
| CVE-2018-20316 | Alta (8.1) | 0.83% | — | 7 ene 2021 | Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read, a different issue than CVE-2018-20310… |
| CVE-2018-20315 | Alta (8.1) | 0.83% | — | 7 ene 2021 | Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a race condition that can cause a stack-based buffer overflow or an out-of-bounds read. |
| CVE-2018-20314 | Alta (8.1) | 0.85% | — | 7 ene 2021 | Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCheckLicence race condition that can cause a stack-based buffer overflow or an out-of-bounds read. |
| CVE-2018-20313 | Alta (8.1) | 0.83% | — | 7 ene 2021 | Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyPreviewAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read. |
| CVE-2018-20312 | Alta (8.1) | 0.83% | — | 7 ene 2021 | Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read, a different issue than CVE-2018-20310… |
| CVE-2018-20311 | Alta (8.1) | 0.83% | — | 7 ene 2021 | Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCPDFAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read. |
| CVE-2018-20310 | Alta (8.1) | 0.87% | — | 7 ene 2021 | Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read. |
| CVE-2018-20309 | Alta (8.1) | 0.83% | — | 7 ene 2021 | Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyGetAppEdition race condition that can cause a stack-based buffer overflow or an out-of-bounds read. |
| CVE-2020-12248 | Alta (8.8) | 1.8% | — | 4 sept 2020 | In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can execute arbitrary code via a heap-based buffer overflow because dirty image-resource data is mishandled. |
| CVE-2020-12247 | Alta (7.1) | 3.6% | — | 4 sept 2020 | In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information from an out-of-bounds read because a text-string index continues to be used after splitting a string… |
| CVE-2020-11493 | Alta (8.1) | 0.93% | — | 4 sept 2020 | In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to Stream without… |
| CVE-2020-15638 | Alta (7.8) | 6.1% | — | 20 ago 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.2.29539. User interaction is required to exploit this vulnerability in that the target must visit a… |
| CVE-2020-15637 | Baja (3.3) | 4.1% | — | 20 ago 2020 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must… |
| CVE-2019-20837 | Alta (7.5) | 1.0% | — | 4 jun 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It allows signature validation bypass via a modified file or a file with non-standard signatures. |
| CVE-2019-20836 | Alta (7.5) | 1.6% | — | 4 jun 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It has mishandling of cloud credentials, as demonstrated by Google Drive. |
| CVE-2019-20835 | Media (4.3) | 0.97% | — | 4 jun 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It has homograph mishandling. |
| CVE-2019-20830 | Crítica (9.8) | 1.7% | — | 4 jun 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has an out-of-bounds write when Internet Explorer is used. |
| CVE-2019-20829 | Alta (7.5) | 1.5% | — | 4 jun 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has a NULL pointer dereference via FXSYS_wcslen in an Epub file. |
| CVE-2019-20828 | Alta (7.5) | 1.5% | — | 4 jun 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has a buffer overflow because a looping correction does not occur after JavaScript updates Field APs. |
| CVE-2019-20827 | Crítica (9.8) | 1.7% | — | 4 jun 2020 | An issue was discovered in Foxit PhantomPDF Mac 3.3 and Foxit Reader for Mac before 3.3. It allows stack consumption because of interaction between ICC-Based color space and Alternate color space. |
| CVE-2019-20826 | Alta (7.5) | 1.5% | — | 4 jun 2020 | An issue was discovered in Foxit PhantomPDF Mac 3.3 and Foxit Reader for Mac before 3.3. It has a NULL pointer dereference. |
| CVE-2018-21240 | Alta (7.5) | 1.0% | — | 4 jun 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows memory consumption via an ArrayBuffer(0xfffffffe) call. |
| CVE-2018-21239 | Media (5.3) | 0.82% | — | 4 jun 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows NTLM credential theft via a GoToE or GoToR action. |