VendorsFoxitpdf_editorany version
Vulnerabilities

Foxit PDF Editor any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

298CVEs
CVE-2022-37379
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the AFSpecial_KeystrokeEx method. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17168.
Published 2023-03-29 · Modified
5.5EPSS 0.009
CVE-2022-37380
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of ADBC objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17169.
Published 2023-03-29 · Modified
5.5EPSS 0.009
CVE-2022-37382
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the removeIcon method. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17383.
Published 2023-03-29 · Modified
5.5EPSS 0.009
CVE-2022-37383
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17111.
Published 2023-03-29 · Modified
5.5EPSS 0.009
CVE-2022-37386
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.2.53575. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the resetForm method. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17550.
Published 2023-03-29 · Modified
5.5EPSS 0.009
CVE-2022-25108
Foxit PDF Reader and Editor before 11.2.1 and PhantomPDF before 10.1.7 allow a NULL pointer dereference during PDF parsing because the pointer is used without proper validation.
Published 2022-03-07 · Modified
5.5EPSS 0.009
CVE-2024-30363
Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-04-02 · Analyzed
5.5EPSS 0.007
CVE-2023-51561
Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2021-34949
Foxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-07 · Analyzed
5.5EPSS 0.003
CVE-2021-34969
Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability
Published 2024-05-07 · Analyzed
5.5EPSS 0.003
CVE-2021-34972
Foxit PDF Reader AcroForm Use-After-Free Information Disclosure Vulnerability
Published 2024-05-07 · Analyzed
5.5EPSS 0.003
CVE-2021-34973
Foxit PDF Reader PDF File Parsing Use-After-Free Information Disclosure Vulnerability
Published 2024-05-07 · Analyzed
5.5EPSS 0.003
CVE-2021-34976
Foxit PDF Reader PDF File Parsing Use-After-Free Information Disclosure Vulnerability
Published 2024-05-07 · Analyzed
5.5EPSS 0.003
CVE-2021-34970
Foxit PDF Reader print Method Use of Externally-Controlled Format String Information Disclosure Vulnerability
Published 2024-05-07 · Analyzed
5.5EPSS 0.003
CVE-2022-25641
Foxit PDF Reader before 11.2.2 and PDF Editor before 11.2.2, and PhantomPDF before 10.1.8, mishandle cross-reference information during compressed-object parsing within signed documents. This leads to delivery of incorrect signature information via an Incremental Saving Attack and a Shadow Attack.
Published 2022-08-29 · Modified
5.5EPSS 0.003
CVE-2021-40326
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An attacker can write to an arbitrary file, and display controlled contents, during signature verification.
Published 2022-08-29 · Modified
5.5EPSS 0.003
CVE-2025-9323
Foxit PDF Reader JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2025-09-02 · Analyzed
5.5EPSS 0.002
CVE-2025-9324
Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2025-09-02 · Analyzed
5.5EPSS 0.002
CVE-2025-9325
Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2025-09-02 · Analyzed
5.5EPSS 0.002
CVE-2025-9327
Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2025-09-02 · Analyzed
5.5EPSS 0.002
CVE-2026-5939
UAF in Foxit PDF Editor/Reader via XFA calculate event
Published 2026-04-27 · Analyzed
5.5EPSS 0.002
CVE-2026-3776
Null pointer dereference in Foxit PDF Editor/Reader when accessing stamp annotation
Published 2026-04-01 · Analyzed
5.5EPSS 0.001
CVE-2026-5942
Foxit PDF Editor/Reader AcroForm Signature Use-After-Free Vulnerability
Published 2026-04-27 · Analyzed
5.5EPSS 0.001
CVE-2026-5938
Foxit PDF Editor/Reader Infinite Loop Denial-of-Service Vulnerability
Published 2026-04-27 · Analyzed
5.5EPSS 0.001
CVE-2026-5937
Foxit PDF Editor/Reader's insufficient parameter validation leads to denial-of-service vulnerability
Published 2026-04-27 · Analyzed
5.5EPSS 0.001
CVE-2026-18622
Foxit PDF Editor/Reader's signature-validation pop-up reports modified certified documents as valid
Published 2026-08-13 · Analyzed
5.5EPSS 0.001
CVE-2025-59803
Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker can embed triggers (e.g., JavaScript) in a PDF document that execute during the signing process. When a signer reviews the document, the content appears normal. However, once the signature is applied, the triggers modify content on other pages or optional content layers without explicit warning. This can cause the signed PDF to differ from what the signer saw, undermining the trustworthiness of the digital signature. The fixed versions are 2025.2.1, 14.0.1, and 13.2.1.
Published 2025-12-11 · Analyzed
5.3EPSS 0.002
CVE-2024-7722
Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability
Published 2024-08-21 · Analyzed
4.3EPSS 0.006
CVE-2022-34873
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16777.
Published 2022-07-18 · Modified
3.3EPSS 0.009
CVE-2022-34874
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.2.53575. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17474.
Published 2022-07-18 · Modified
3.3EPSS 0.009
CVE-2022-34875
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of ADBC objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16981.
Published 2022-07-18 · Modified
3.3EPSS 0.009
CVE-2022-37376
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Editor 11.1.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of arrays. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16599.
Published 2023-03-29 · Modified
3.3EPSS 0.008
CVE-2024-30329
Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability
Published 2024-04-03 · Analyzed
3.3EPSS 0.007
CVE-2024-30364
Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-04-02 · Analyzed
3.3EPSS 0.006
CVE-2024-30347
Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-04-02 · Analyzed
3.3EPSS 0.006
CVE-2023-42093
Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability
Published 2024-05-03 · Modified
3.3EPSS 0.005
CVE-2024-30350
Foxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-04-02 · Analyzed
3.3EPSS 0.005
CVE-2023-38113
Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
3.3EPSS 0.005
CVE-2023-42098
Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
3.3EPSS 0.005
CVE-2023-42095
Foxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Modified
3.3EPSS 0.005
← Prev7 / 8Next →