Show filters
418 Total Results
Displaying 331-340 of 418
Sort by:
Attacker Value
Unknown

CVE-2021-41783

Disclosure Date: August 29, 2022 (last updated February 24, 2025)
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
Attacker Value
Unknown

CVE-2021-41782

Disclosure Date: August 29, 2022 (last updated February 24, 2025)
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
Attacker Value
Unknown

CVE-2021-41781

Disclosure Date: August 29, 2022 (last updated February 24, 2025)
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
Attacker Value
Unknown

CVE-2021-41780

Disclosure Date: August 29, 2022 (last updated February 24, 2025)
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
Attacker Value
Unknown

CVE-2021-40326

Disclosure Date: August 29, 2022 (last updated February 24, 2025)
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An attacker can write to an arbitrary file, and display controlled contents, during signature verification.
Attacker Value
Unknown

CVE-2022-26979

Disclosure Date: August 06, 2022 (last updated February 24, 2025)
Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL.
Attacker Value
Unknown

CVE-2022-27944

Disclosure Date: August 06, 2022 (last updated February 24, 2025)
Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow an exportXFAData NULL pointer dereference.
Attacker Value
Unknown

CVE-2022-34875

Disclosure Date: July 18, 2022 (last updated February 24, 2025)
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of ADBC objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16981.
Attacker Value
Unknown

CVE-2022-34874

Disclosure Date: July 18, 2022 (last updated February 24, 2025)
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.2.53575. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17474.
Attacker Value
Unknown

CVE-2022-34873

Disclosure Date: July 18, 2022 (last updated February 24, 2025)
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16777.