Foxit / Foxit Reader
376 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-32451 | A memory corruption vulnerability exists in Foxit Reader 2025.1.0.27937 due to the use of an uninitialized pointer. A specially crafted Javascript code inside… | HIGH | 8.8 | Aug 13, 2025 |
| CVE-2013-10068 | Foxit Reader <= 5.4.5.0114 Plugin URL Processing Buffer Overflow | CRITICAL | 9.4 | Aug 5, 2025 |
| CVE-2024-49576 | A use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a checkbox CBF_Widget object. A specially crafted Javascript code inside a… | HIGH | 8.8 | Dec 18, 2024 |
| CVE-2024-47810 | A use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a 3D page object. A specially crafted Javascript code inside a malicious P… | HIGH | 8.8 | Dec 18, 2024 |
| CVE-2024-28888 | A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a checkbox field object. A specially crafted Javascript code inside a mali… | HIGH | 8.8 | Oct 2, 2024 |
| CVE-2024-29072 | A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the update… | HIGH | 8.2 | May 28, 2024 |
| CVE-2024-25938 | A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Barcode widget. A specially crafted JavaScript code inside a malicious P… | HIGH | 8.8 | Apr 30, 2024 |
| CVE-2024-25648 | A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a ComboBox widget. A specially crafted JavaScript code inside a malicious… | HIGH | 8.8 | Apr 30, 2024 |
| CVE-2024-25575 | A type confusion vulnerability vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Lock object. A specially crafted Javascript code inside a… | HIGH | 8.8 | Apr 30, 2024 |
| CVE-2023-39542 | A code execution vulnerability exists in the Javascript saveAs API of Foxit Reader 12.1.3.15356. A specially crafted malformed file can create arbitrary files,… | HIGH | 8.8 | Nov 27, 2023 |
| CVE-2023-40194 | An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to mistreatment of whitespace character… | HIGH | 8.8 | Nov 27, 2023 |
| CVE-2023-35985 | An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to a failure to properly validate a dan… | HIGH | 8.8 | Nov 27, 2023 |
| CVE-2023-32616 | A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles 3D annotations. A specially crafted Javascript code inside a malicious PDF d… | HIGH | 8.8 | Nov 27, 2023 |
| CVE-2023-41257 | A type confusion vulnerability exists in the way Foxit Reader 12.1.2.15356 handles field value properties. A specially crafted Javascript code inside a malicio… | HIGH | 8.8 | Nov 27, 2023 |
| CVE-2023-38573 | A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles a signature field. A specially crafted Javascript code inside a malicious PD… | HIGH | 8.8 | Nov 27, 2023 |
| CVE-2023-28744 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.1.1.15289. A specially crafted PDF document can trigg… | HIGH | 8.8 | Jul 19, 2023 |
| CVE-2023-27379 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 12.1.2.15332. By prematurely deleting objects associated… | HIGH | 8.8 | Jul 19, 2023 |
| CVE-2023-33866 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 12.1.2.15332. By prematurely deleting objects associated… | HIGH | 8.8 | Jul 19, 2023 |
| CVE-2023-32664 | A type confusion vulnerability exists in the Javascript checkThisBox method as implemented in Foxit Reader 12.1.2.15332. Specially crafted Javascript code insi… | HIGH | 8.8 | Jul 19, 2023 |
| CVE-2023-33876 | A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15332 handles destroying annotations. Specially crafted Javascript code inside a malicious… | HIGH | 8.8 | Jul 19, 2023 |
| CVE-2022-40129 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A specially-crafted PDF document can trigg… | HIGH | 7.8 | Nov 21, 2022 |
| CVE-2022-38097 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely destroying annotation objec… | HIGH | 7.8 | Nov 21, 2022 |
| CVE-2022-37332 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A specially-crafted PDF document can trigg… | HIGH | 7.8 | Nov 21, 2022 |
| CVE-2022-32774 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely deleting objects associated… | HIGH | 7.8 | Nov 21, 2022 |
| CVE-2022-43310 | An Uncontrolled Search Path Element in Foxit Software released Foxit Reader v11.2.118.51569 allows attackers to escalate privileges when searching for DLL libr… | HIGH | 7.8 | Nov 9, 2022 |
Showing 1 to 25 of 376 CVEs