VendorsFoxitpdf_readerany version
Vulnerabilities

Foxit PDF Reader any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

320CVEs
CVE-2025-9327
Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2025-09-02 · Analyzed
5.5EPSS 0.002
CVE-2020-35990
Buffer Overflow vulnerability in cFilenameInit parameter in browseForDoc function in Foxit Software Foxit PDF Reader version 10.1.0.37527, allows local attackers to cause a denial of service (DoS) via crafted .pdf file.
Published 2023-08-11 · Modified
5.5EPSS 0.002
CVE-2026-5939
UAF in Foxit PDF Editor/Reader via XFA calculate event
Published 2026-04-27 · Analyzed
5.5EPSS 0.002
CVE-2026-3776
Null pointer dereference in Foxit PDF Editor/Reader when accessing stamp annotation
Published 2026-04-01 · Analyzed
5.5EPSS 0.001
CVE-2026-5937
Foxit PDF Editor/Reader's insufficient parameter validation leads to denial-of-service vulnerability
Published 2026-04-27 · Analyzed
5.5EPSS 0.001
CVE-2026-5938
Foxit PDF Editor/Reader Infinite Loop Denial-of-Service Vulnerability
Published 2026-04-27 · Analyzed
5.5EPSS 0.001
CVE-2026-5942
Foxit PDF Editor/Reader AcroForm Signature Use-After-Free Vulnerability
Published 2026-04-27 · Analyzed
5.5EPSS 0.001
CVE-2026-18622
Foxit PDF Editor/Reader's signature-validation pop-up reports modified certified documents as valid
Published 2026-08-13 · Analyzed
5.5EPSS 0.001
CVE-2025-59803
Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker can embed triggers (e.g., JavaScript) in a PDF document that execute during the signing process. When a signer reviews the document, the content appears normal. However, once the signature is applied, the triggers modify content on other pages or optional content layers without explicit warning. This can cause the signed PDF to differ from what the signer saw, undermining the trustworthiness of the digital signature. The fixed versions are 2025.2.1, 14.0.1, and 13.2.1.
Published 2025-12-11 · Analyzed
5.3EPSS 0.002
CVE-2024-7722
Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability
Published 2024-08-21 · Analyzed
4.3EPSS 0.006
CVE-2022-34873
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16777.
Published 2022-07-18 · Modified
3.3EPSS 0.009
CVE-2022-34874
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.2.53575. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17474.
Published 2022-07-18 · Modified
3.3EPSS 0.009
CVE-2022-34875
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of ADBC objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16981.
Published 2022-07-18 · Modified
3.3EPSS 0.009
CVE-2022-37376
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Editor 11.1.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of arrays. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16599.
Published 2023-03-29 · Modified
3.3EPSS 0.008
CVE-2024-30329
Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability
Published 2024-04-03 · Analyzed
3.3EPSS 0.007
CVE-2024-30364
Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-04-02 · Analyzed
3.3EPSS 0.006
CVE-2024-30347
Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-04-02 · Analyzed
3.3EPSS 0.006
CVE-2023-42093
Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability
Published 2024-05-03 · Modified
3.3EPSS 0.005
CVE-2024-30350
Foxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-04-02 · Analyzed
3.3EPSS 0.005
CVE-2023-38113
Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
3.3EPSS 0.005
CVE-2023-42098
Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
3.3EPSS 0.005
CVE-2023-42095
Foxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Modified
3.3EPSS 0.005
CVE-2023-38109
Foxit PDF Reader Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
3.3EPSS 0.005
CVE-2023-38110
Foxit PDF Reader AcroForm Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
3.3EPSS 0.005
CVE-2024-30340
Foxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-04-02 · Analyzed
3.3EPSS 0.005
CVE-2024-30356
Foxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-04-02 · Analyzed
3.3EPSS 0.005
CVE-2023-38108
Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
3.3EPSS 0.005
CVE-2023-38115
Foxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
3.3EPSS 0.005
CVE-2023-38116
Foxit PDF Reader Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
3.3EPSS 0.005
CVE-2023-38105
Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
3.3EPSS 0.005
CVE-2023-38106
Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
3.3EPSS 0.005
CVE-2023-51554
Foxit PDF Reader Signature Use-After-Free Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
3.3EPSS 0.004
CVE-2023-51555
Foxit PDF Reader Doc Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
3.3EPSS 0.004
CVE-2023-51558
Foxit PDF Reader AcroForm Doc Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
3.3EPSS 0.004
CVE-2023-51562
Foxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
3.3EPSS 0.004
CVE-2023-51550
Foxit PDF Reader combobox Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
3.3EPSS 0.004
CVE-2023-51553
Foxit PDF Reader Bookmark Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
3.3EPSS 0.004
CVE-2021-34951
Foxit PDF Reader Annotation Use of Uninitialized Variable Information Disclosure Vulnerability
Published 2024-05-07 · Analyzed
3.3EPSS 0.003
CVE-2023-51559
Foxit PDF Reader Doc Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
3.3EPSS 0.003
CVE-2025-55307
An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. Opening a malicious PDF containing a crafted JavaScript call to search.query() with a crafted cDIPath parameter (e.g., "/") may cause an out-of-bounds read in internal path-parsing logic, potentially leading to information disclosure or memory corruption.
Published 2025-12-11 · Analyzed
3.3EPSS 0.002
← Prev8 / 8