Show filters
596 Total Results
Displaying 91-100 of 596
Sort by:
Attacker Value
Unknown
CVE-2020-26534
Disclosure Date: October 02, 2020 (last updated February 22, 2025)
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Field::ClearItems and Field::DeleteOptions, during AcroForm JavaScript execution.
0
Attacker Value
Unknown
CVE-2020-26540
Disclosure Date: October 02, 2020 (last updated February 22, 2025)
An issue was discovered in Foxit Reader and PhantomPDF before 4.1 on macOS. Because the Hardened Runtime protection mechanism is not applied to code signing, code injection (or an information leak) can occur.
0
Attacker Value
Unknown
CVE-2020-11493
Disclosure Date: September 04, 2020 (last updated February 22, 2025)
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to Stream without concern for a crafted XObject.
0
Attacker Value
Unknown
CVE-2020-12247
Disclosure Date: September 04, 2020 (last updated February 22, 2025)
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information from an out-of-bounds read because a text-string index continues to be used after splitting a string into two parts. A crash may also occur.
0
Attacker Value
Unknown
CVE-2020-12248
Disclosure Date: September 04, 2020 (last updated February 22, 2025)
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can execute arbitrary code via a heap-based buffer overflow because dirty image-resource data is mishandled.
0
Attacker Value
Unknown
CVE-2020-15637
Disclosure Date: August 20, 2020 (last updated February 22, 2025)
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the SetLocalDescription method. By performing actions in JavaScript, an attacker can cause a pointer to be reused after it has been freed. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-10972.
0
Attacker Value
Unknown
CVE-2020-15638
Disclosure Date: August 20, 2020 (last updated February 22, 2025)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.2.29539. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the NodeProperties::InferReceiverMapsUnsafe method. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-10950.
0
Attacker Value
Unknown
CVE-2019-20836
Disclosure Date: June 04, 2020 (last updated February 21, 2025)
An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It has mishandling of cloud credentials, as demonstrated by Google Drive.
0
Attacker Value
Unknown
CVE-2019-20828
Disclosure Date: June 04, 2020 (last updated February 21, 2025)
An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has a buffer overflow because a looping correction does not occur after JavaScript updates Field APs.
0
Attacker Value
Unknown
CVE-2019-20827
Disclosure Date: June 04, 2020 (last updated February 21, 2025)
An issue was discovered in Foxit PhantomPDF Mac 3.3 and Foxit Reader for Mac before 3.3. It allows stack consumption because of interaction between ICC-Based color space and Alternate color space.
0