Vulnerabilities > Foxitsoftware

DATE CVE VULNERABILITY TITLE RISK
2016-10-31 CVE-2016-8879 Out-of-bounds Write vulnerability in Foxitsoftware Phantompdf and Reader
The thumbnail shell extension plugin (FoxitThumbnailHndlr_x86.dll) in Foxit Reader and PhantomPDF before 8.1 on Windows allows remote attackers to cause a denial of service (out-of-bounds write and application crash) via a crafted JPEG2000 image embedded in a PDF document, aka an "Exploitable - Heap Corruption" issue.
network
low complexity
foxitsoftware CWE-787
6.5
2016-10-31 CVE-2016-8878 Out-of-bounds Read vulnerability in Foxitsoftware Phantompdf and Reader
Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute arbitrary code via a crafted BMP image embedded in the XFA stream in a PDF document, aka "Data from Faulting Address may be used as a return value starting at FOXITREADER."
network
low complexity
foxitsoftware CWE-125
8.8
2016-10-31 CVE-2016-8877 Out-of-bounds Write vulnerability in Foxitsoftware Phantompdf and Reader
Heap buffer overflow (Out-of-Bounds write) vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows allows remote attackers to execute arbitrary code via a crafted JPEG2000 image embedded in a PDF document, aka a "corrupted suffix pattern" issue.
network
low complexity
foxitsoftware CWE-787
8.8
2016-10-31 CVE-2016-8876 Out-of-bounds Read vulnerability in Foxitsoftware Phantompdf and Reader
Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF image embedded in the XFA stream in a PDF document, aka "Read Access Violation starting at FoxitReader."
network
high complexity
foxitsoftware CWE-125
7.5
2016-10-31 CVE-2016-8875 Out-of-bounds Read vulnerability in Foxitsoftware Phantompdf and Reader
The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image, aka "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at ConvertToPDF_x86!CreateFXPDFConvertor."
network
high complexity
foxitsoftware CWE-125
5.3
2016-10-31 CVE-2016-8856 Permission Issues vulnerability in Foxitsoftware Reader 2.1.0.0804/2.1.0.0805
Foxit Reader for Mac 2.1.0.0804 and earlier and Foxit Reader for Linux 2.1.0.0805 and earlier suffered from a vulnerability where weak file permissions could be exploited by attackers to execute arbitrary code.
local
low complexity
foxitsoftware CWE-275
7.8
2016-04-22 CVE-2016-4065 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Foxitsoftware Foxit Reader and Phantompdf
The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 7.3.4 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted (1) JPEG, (2) GIF, or (3) BMP image.
local
low complexity
foxitsoftware CWE-119
7.8
2016-04-22 CVE-2016-4064 Improper Access Control vulnerability in Foxitsoftware Foxit Reader and Phantompdf
Use-after-free vulnerability in the XFA forms handling functionality in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via a crafted remerge call.
local
low complexity
foxitsoftware CWE-284
7.8
2016-04-22 CVE-2016-4063 Unspecified vulnerability in Foxitsoftware Foxit Reader and Phantompdf
Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via an object with a revision number of -1 in a PDF document.
local
low complexity
foxitsoftware
7.8
2016-04-22 CVE-2016-4062 Data Processing Errors vulnerability in Foxitsoftware Foxit Reader and Phantompdf
Foxit Reader and PhantomPDF before 7.3.4 on Windows improperly report format errors recursively, which allows remote attackers to cause a denial of service (application hang) via a crafted PDF.
local
low complexity
foxitsoftware CWE-19
5.5