Show filters
558 Total Results
Displaying 1-10 of 558
Sort by:
Attacker Value
Unknown

CVE-2022-25641

Disclosure Date: August 29, 2022 (last updated October 08, 2023)
Foxit PDF Reader before 11.2.2 and PDF Editor before 11.2.2, and PhantomPDF before 10.1.8, mishandle cross-reference information during compressed-object parsing within signed documents. This leads to delivery of incorrect signature information via an Incremental Saving Attack and a Shadow Attack.
Attacker Value
Unknown

CVE-2021-41785

Disclosure Date: August 29, 2022 (last updated October 08, 2023)
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
Attacker Value
Unknown

CVE-2021-41784

Disclosure Date: August 29, 2022 (last updated October 08, 2023)
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
Attacker Value
Unknown

CVE-2021-41783

Disclosure Date: August 29, 2022 (last updated October 08, 2023)
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
Attacker Value
Unknown

CVE-2021-41782

Disclosure Date: August 29, 2022 (last updated October 08, 2023)
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
Attacker Value
Unknown

CVE-2021-41781

Disclosure Date: August 29, 2022 (last updated October 08, 2023)
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
Attacker Value
Unknown

CVE-2021-41780

Disclosure Date: August 29, 2022 (last updated October 08, 2023)
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.
Attacker Value
Unknown

CVE-2021-40326

Disclosure Date: August 29, 2022 (last updated October 08, 2023)
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An attacker can write to an arbitrary file, and display controlled contents, during signature verification.
Attacker Value
Unknown

CVE-2021-38574

Disclosure Date: August 11, 2021 (last updated November 28, 2024)
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.
Attacker Value
Unknown

CVE-2021-38573

Disclosure Date: August 11, 2021 (last updated November 28, 2024)
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not validated.