VendorsFoxitpdf_readerany version
Vulnerabilities

Foxit PDF Reader any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

320CVEs
CVE-2026-3775
Foxit PDF Editor/Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
Published 2026-04-01 · Analyzed
7.8EPSS 0.002
CVE-2026-57240
Foxit PDF Editor/Reader Form Field Use-After-Free Remote Code Execution Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2025-9330
Foxit PDF Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
Published 2025-09-02 · Analyzed
7.8EPSS 0.002
CVE-2025-55313
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. They allow potential arbitrary code execution when processing crafted PDF files. The vulnerability stems from insufficient handling of memory allocation failures after assigning an extremely large value to a form field's charLimit property via JavaScript. This can result in memory corruption and may allow an attacker to execute arbitrary code by persuading a user to open a malicious file.
Published 2025-12-11 · Analyzed
7.8EPSS 0.002
CVE-2026-57256
Foxit Editor/Reader List Box Format Use-After-Free Vulnerability
Published 2026-07-08 · Modified
7.8EPSS 0.002
CVE-2026-3777
Use after free of view cache in Foxit PDF Editor/Reader
Published 2026-04-01 · Analyzed
7.8EPSS 0.002
CVE-2026-3780
Foxit PDF Editor/Reader Installer Uncontrolled Search Path Privilege Escalation
Published 2026-04-01 · Analyzed
7.8EPSS 0.002
CVE-2026-57260
Security vulnerability in Foxit PDF Editor/Reader — U3D Adobe Mesh Decompression (Type Confusion / Invalid Pointer Dereference)
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-57249
Foxit PDF Editor/Reader Annotation Use-After-Free Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-57242
Foxit PDF Editor/Reader Page Use-After-Free Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-5943
Foxit PDF Editor/Reader AcroForm Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2026-04-27 · Analyzed
7.8EPSS 0.002
CVE-2026-57250
Foxit PDF Editor/Reader Form Field Use-After-Free Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-57247
Foxit PDF Editor/Reader Field Use-After-Free Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-57248
Foxit PDF Editor/Reader Annotation Improper Release Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-13129
Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-13127
Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-13128
Foxit PDF Editor/Reader Doc Object Use-After-Free Remote Code Execution Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-57254
Foxit PDF Editor/Reader Annotation Type Confusion Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-57238
Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-57237
Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-57252
Foxit PDF Editor/Reader AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-57251
Foxit PDF Editor/Reader Cloud Appearance Buffer Overflow Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-57246
Foxit PDF Editor/Reader Signature Buffer Overflow Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-13126
Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-57245
Foxit PDF Editor/Reader Signature Hyperlink Use-After-Free Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-57244
Foxit PDF Editor/Reader Form Control Use-After-Free Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-5941
Foxit PDF Editor/Reader AcroForm Signature Remote Code Execution Vulnerability
Published 2026-04-27 · Analyzed
7.8EPSS 0.002
CVE-2026-5940
Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2026-04-27 · Analyzed
7.8EPSS 0.002
CVE-2023-33240
Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x versions, 11.2.5.53785 and all previous 11.x versions, and 10.1.11.37866 and earlier) on Windows allows Local Privilege Escalation when installed to a non-default directory because unprivileged users have access to an executable file of a system service. This is fixed in 12.1.2.
Published 2023-05-19 · Modified
7.8EPSS 0.002
CVE-2024-32488
In Foxit PDF Reader and Editor before 2024.1, Local Privilege Escalation could occur during update checks because weak permissions on the update-service folder allow attackers to place crafted DLL files there.
Published 2024-04-15 · Analyzed
7.8EPSS 0.002
CVE-2025-55312
An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume these states are valid, causing dereference of invalid or released memory. This can lead to memory corruption, application crashes, and potentially allow an attacker to execute arbitrary code.
Published 2025-12-11 · Analyzed
7.8EPSS 0.002
CVE-2022-30557
Foxit PDF Reader and PDF Editor before 11.2.2 have a Type Confusion issue that causes a crash because of Unsigned32 mishandling during JavaScript execution.
Published 2022-05-11 · Modified
7.5EPSS 0.044
CVE-2022-26979
Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL.
Published 2022-08-06 · Modified
7.5EPSS 0.011
CVE-2022-27944
Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow an exportXFAData NULL pointer dereference.
Published 2022-08-06 · Modified
7.5EPSS 0.011
CVE-2021-38567
An issue was discovered in Foxit PDF Editor before 11.0.1 and PDF Reader before 11.0.1 on macOS. It mishandles missing dictionary entries, leading to a NULL pointer dereference, aka CNVD-C-2021-95204.
Published 2021-08-11 · Modified
7.5EPSS 0.010
CVE-2025-59802
Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via OCG. When Optional Content Groups (OCG) are supported, the state property of an OCG is runtime-only and not included in the digital signature computation buffer. An attacker can leverage JavaScript or PDF triggers to dynamically change the visibility of OCG content after signing (Post-Sign), allowing the visual content of a signed PDF to be modified without invalidating the signature. This may result in a mismatch between the signed content and what the signer or verifier sees, undermining the trustworthiness of the digital signature. The fixed versions are 2025.2.1, 14.0.1, and 13.2.1.
Published 2025-12-11 · Analyzed
7.5EPSS 0.003
CVE-2026-3774
Self-Modifications Affecting Altered Printing and Redaction in Foxit PDF Editor
Published 2026-04-01 · Analyzed
7.5EPSS 0.002
CVE-2024-12753
Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability
Published 2024-12-30 · Analyzed
7.3EPSS 0.003
CVE-2025-55310
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. An attacker able to alter or replace the static HTML files used by the StartPage feature can cause the application to load malicious or compromised content upon startup. This may result in information disclosure, unauthorized data access, or other security impacts.
Published 2025-12-11 · Analyzed
7.3EPSS 0.001
CVE-2024-30335
Foxit PDF Reader AcroForm Annotation Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-04-02 · Analyzed
7.1EPSS 0.007
← Prev6 / 8Next →