VendorsFoxitpdf_readerany version
Vulnerabilities

Foxit PDF Reader any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

320CVEs
CVE-2023-42090
Foxit PDF Reader XFA Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Modified
7.1EPSS 0.005
CVE-2024-9246
Foxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-11-22 · Analyzed
7.1EPSS 0.005
CVE-2024-9253
Foxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-11-22 · Analyzed
7.1EPSS 0.004
CVE-2024-9256
Foxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-11-22 · Analyzed
7.1EPSS 0.004
CVE-2025-55308
An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. A crafted PDF containing JavaScript that calls closeDoc() while internal objects are still in use can cause premature release of these objects. This use-after-free vulnerability may lead to memory corruption, potentially resulting in information disclosure when the PDF is opened.
Published 2025-12-11 · Analyzed
6.7EPSS 0.001
CVE-2025-55309
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can contain JavaScript that attaches an OnBlur action on a form field that destroys an annotation. During user right-click interaction, the program's internal focus change handling prematurely releases the annotation object, resulting in a use-after-free vulnerability that may cause memory corruption or application crashes.
Published 2025-12-11 · Analyzed
6.7EPSS 0.001
CVE-2022-24368
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16115.
Published 2022-02-18 · Modified
6.5EPSS 0.021
CVE-2022-24370
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader Foxit reader 11.0.1.0719 macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of XFA forms. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-14819.
Published 2022-02-18 · Modified
6.5EPSS 0.019
CVE-2022-47881
Foxit PDF Reader and PDF Editor 11.2.1.53537 and earlier has an Out-of-Bounds Read vulnerability.
Published 2023-01-18 · Modified
6.5EPSS 0.007
CVE-2026-57259
Foxit PDF Editor/Reader XDP XFA XXE arbitrary local file read
Published 2026-07-08 · Analyzed
6.5EPSS 0.004
CVE-2025-55311
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can use JavaScript to alter annotation content and subsequently clear the file's modification status via JavaScript interfaces. This circumvents digital signature verification by hiding document modifications, allowing an attacker to mislead users about the document's integrity and compromise the trustworthiness of signed PDFs.
Published 2025-12-11 · Modified
6.5EPSS 0.002
CVE-2026-3778
Stack exhaustion caused by cyclic references in Foxit PDF Editor/Reader
Published 2026-04-01 · Analyzed
6.2EPSS 0.001
CVE-2022-28681
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the deletePages method. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16825.
Published 2022-07-18 · Modified
6.1EPSS 0.009
CVE-2026-57258
Foxit PDF Editor/Reader Crash via Malformed PRC 3D Stream
Published 2026-07-08 · Analyzed
6.1EPSS 0.002
CVE-2026-57257
Security vulnerability in Foxit PDF Editor/Reader — PRC 3D BRep Renderer Heap OOB Read
Published 2026-07-08 · Analyzed
6.1EPSS 0.002
CVE-2026-57253
Foxit PDF Editor/Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2026-07-08 · Analyzed
6.1EPSS 0.002
CVE-2026-57243
Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability
Published 2026-07-08 · Analyzed
6.1EPSS 0.002
CVE-2026-57241
Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability
Published 2026-07-08 · Analyzed
6.1EPSS 0.002
CVE-2026-57255
Security vulnerability in Foxit PDF Editor/Reader — OOB Read via NaN-Bypass Clamp
Published 2026-07-08 · Analyzed
6.1EPSS 0.002
CVE-2022-27359
Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a this.maildoc NULL pointer dereference.
Published 2022-05-05 · Modified
5.5EPSS 0.011
CVE-2022-43640
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 12.0.1.12430. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18629.
Published 2023-03-29 · Modified
5.5EPSS 0.009
CVE-2022-37379
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the AFSpecial_KeystrokeEx method. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17168.
Published 2023-03-29 · Modified
5.5EPSS 0.009
CVE-2022-37380
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of ADBC objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17169.
Published 2023-03-29 · Modified
5.5EPSS 0.009
CVE-2022-37382
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the removeIcon method. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17383.
Published 2023-03-29 · Modified
5.5EPSS 0.009
CVE-2022-37383
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17111.
Published 2023-03-29 · Modified
5.5EPSS 0.009
CVE-2022-37386
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.2.53575. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the resetForm method. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17550.
Published 2023-03-29 · Modified
5.5EPSS 0.009
CVE-2022-25108
Foxit PDF Reader and Editor before 11.2.1 and PhantomPDF before 10.1.7 allow a NULL pointer dereference during PDF parsing because the pointer is used without proper validation.
Published 2022-03-07 · Modified
5.5EPSS 0.009
CVE-2024-30363
Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-04-02 · Analyzed
5.5EPSS 0.007
CVE-2023-51561
Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2021-34969
Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability
Published 2024-05-07 · Analyzed
5.5EPSS 0.003
CVE-2021-34972
Foxit PDF Reader AcroForm Use-After-Free Information Disclosure Vulnerability
Published 2024-05-07 · Analyzed
5.5EPSS 0.003
CVE-2021-34973
Foxit PDF Reader PDF File Parsing Use-After-Free Information Disclosure Vulnerability
Published 2024-05-07 · Analyzed
5.5EPSS 0.003
CVE-2021-34976
Foxit PDF Reader PDF File Parsing Use-After-Free Information Disclosure Vulnerability
Published 2024-05-07 · Analyzed
5.5EPSS 0.003
CVE-2021-34949
Foxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-07 · Analyzed
5.5EPSS 0.003
CVE-2021-34970
Foxit PDF Reader print Method Use of Externally-Controlled Format String Information Disclosure Vulnerability
Published 2024-05-07 · Analyzed
5.5EPSS 0.003
CVE-2022-25641
Foxit PDF Reader before 11.2.2 and PDF Editor before 11.2.2, and PhantomPDF before 10.1.8, mishandle cross-reference information during compressed-object parsing within signed documents. This leads to delivery of incorrect signature information via an Incremental Saving Attack and a Shadow Attack.
Published 2022-08-29 · Modified
5.5EPSS 0.003
CVE-2021-40326
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An attacker can write to an arbitrary file, and display controlled contents, during signature verification.
Published 2022-08-29 · Modified
5.5EPSS 0.003
CVE-2025-9323
Foxit PDF Reader JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2025-09-02 · Analyzed
5.5EPSS 0.002
CVE-2025-9324
Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2025-09-02 · Analyzed
5.5EPSS 0.002
CVE-2025-9325
Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2025-09-02 · Analyzed
5.5EPSS 0.002
← Prev7 / 8Next →