Show filters
158 Total Results
Displaying 1-10 of 158
Sort by:
Attacker Value
Unknown
CVE-2018-19418
Disclosure Date: January 07, 2021 (last updated February 22, 2025)
Foxit PDF ActiveX before 5.5.1 allows remote code execution via command injection because of the lack of a security permission control.
0
Attacker Value
Unknown
CVE-2019-19161
Disclosure Date: June 30, 2020 (last updated February 21, 2025)
CyMiInstaller322 ActiveX which runs MIPLATFORM downloads files required to run applications. A vulnerability in downloading files by CyMiInstaller322 ActiveX caused by an attacker to download randomly generated DLL files and MIPLATFORM to load those DLLs due to insufficient verification.
0
Attacker Value
Unknown
CVE-2019-19165
Disclosure Date: April 29, 2020 (last updated February 21, 2025)
AxECM.cab(ActiveX Control) in Inogard Ebiz4u contains a vulnerability that could allow remote files to be downloaded and executed by setting arguments to the activeX method. Download of Code Without Integrity Check vulnerability in ActiveX control of Inogard Co,,LTD Ebiz4u ActiveX of Inogard Co,,LTD(AxECM.cab) allows ATTACKER to cause a file download to Windows user's folder and execute. This issue affects: Inogard Co,,LTD Ebiz4u ActiveX of Inogard Co,,LTD(AxECM.cab) version 1.0.5.0 and later versions on windows 7/8/10.
0
Attacker Value
Unknown
CVE-2012-5389
Disclosure Date: January 23, 2020 (last updated February 21, 2025)
NULL Pointer Dereference in PowerTCP WebServer for ActiveX 1.9.2 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted HTTP request.
0
Attacker Value
Unknown
CVE-2019-12809
Disclosure Date: August 15, 2019 (last updated November 27, 2024)
Yes24ViewerX ActiveX Control 1.0.327.50126 and earlier versions contains a vulnerability that could allow remote attackers to download and execute arbitrary files by setting the arguments to the ActiveX method. This can be leveraged for code execution.
0
Attacker Value
Unknown
CVE-2018-19450
Disclosure Date: June 17, 2019 (last updated November 27, 2024)
A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when parsing a launch action. An attacker can leverage this to gain remote code execution.
0
Attacker Value
Unknown
CVE-2018-19446
Disclosure Date: June 17, 2019 (last updated November 27, 2024)
A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API Doc.createDataObject is used. An attacker can leverage this to gain remote code execution.
0
Attacker Value
Unknown
CVE-2018-19448
Disclosure Date: June 17, 2019 (last updated November 27, 2024)
In Foxit Reader SDK (ActiveX) Professional 5.4.0.1031, an uninitialized object in IReader_ContentProvider::GetDocEventHandler occurs when embedding the control into Office documents. By opening a specially crafted document, an attacker can trigger an out of bounds write condition, possibly leveraging this to gain remote code execution.
0
Attacker Value
Unknown
CVE-2018-19445
Disclosure Date: June 17, 2019 (last updated November 27, 2024)
A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API app.launchURL is used. An attacker can leverage this to gain remote code execution.
0
Attacker Value
Unknown
CVE-2018-19444
Disclosure Date: June 17, 2019 (last updated November 27, 2024)
A use after free in the TextBox field Validate action in IReader_ContentProvider can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031. An attacker can leverage this to gain remote code execution. Relative to CVE-2018-19452, this has a different free location and requires different JavaScript code for exploitation.
0