Show filters
158 Total Results
Displaying 1-10 of 158
Sort by:
Attacker Value
Unknown

CVE-2018-19418

Disclosure Date: January 07, 2021 (last updated February 22, 2025)
Foxit PDF ActiveX before 5.5.1 allows remote code execution via command injection because of the lack of a security permission control.
Attacker Value
Unknown

CVE-2019-19161

Disclosure Date: June 30, 2020 (last updated February 21, 2025)
CyMiInstaller322 ActiveX which runs MIPLATFORM downloads files required to run applications. A vulnerability in downloading files by CyMiInstaller322 ActiveX caused by an attacker to download randomly generated DLL files and MIPLATFORM to load those DLLs due to insufficient verification.
Attacker Value
Unknown

CVE-2019-19165

Disclosure Date: April 29, 2020 (last updated February 21, 2025)
AxECM.cab(ActiveX Control) in Inogard Ebiz4u contains a vulnerability that could allow remote files to be downloaded and executed by setting arguments to the activeX method. Download of Code Without Integrity Check vulnerability in ActiveX control of Inogard Co,,LTD Ebiz4u ActiveX of Inogard Co,,LTD(AxECM.cab) allows ATTACKER to cause a file download to Windows user's folder and execute. This issue affects: Inogard Co,,LTD Ebiz4u ActiveX of Inogard Co,,LTD(AxECM.cab) version 1.0.5.0 and later versions on windows 7/8/10.
Attacker Value
Unknown

CVE-2012-5389

Disclosure Date: January 23, 2020 (last updated February 21, 2025)
NULL Pointer Dereference in PowerTCP WebServer for ActiveX 1.9.2 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted HTTP request.
Attacker Value
Unknown

CVE-2019-12809

Disclosure Date: August 15, 2019 (last updated November 27, 2024)
Yes24ViewerX ActiveX Control 1.0.327.50126 and earlier versions contains a vulnerability that could allow remote attackers to download and execute arbitrary files by setting the arguments to the ActiveX method. This can be leveraged for code execution.
Attacker Value
Unknown

CVE-2018-19450

Disclosure Date: June 17, 2019 (last updated November 27, 2024)
A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when parsing a launch action. An attacker can leverage this to gain remote code execution.
0
Attacker Value
Unknown

CVE-2018-19446

Disclosure Date: June 17, 2019 (last updated November 27, 2024)
A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API Doc.createDataObject is used. An attacker can leverage this to gain remote code execution.
0
Attacker Value
Unknown

CVE-2018-19448

Disclosure Date: June 17, 2019 (last updated November 27, 2024)
In Foxit Reader SDK (ActiveX) Professional 5.4.0.1031, an uninitialized object in IReader_ContentProvider::GetDocEventHandler occurs when embedding the control into Office documents. By opening a specially crafted document, an attacker can trigger an out of bounds write condition, possibly leveraging this to gain remote code execution.
0
Attacker Value
Unknown

CVE-2018-19445

Disclosure Date: June 17, 2019 (last updated November 27, 2024)
A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API app.launchURL is used. An attacker can leverage this to gain remote code execution.
0
Attacker Value
Unknown

CVE-2018-19444

Disclosure Date: June 17, 2019 (last updated November 27, 2024)
A use after free in the TextBox field Validate action in IReader_ContentProvider can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031. An attacker can leverage this to gain remote code execution. Relative to CVE-2018-19452, this has a different free location and requires different JavaScript code for exploitation.
0