Vulnerabilities > Foxitsoftware

DATE CVE VULNERABILITY TITLE RISK
2016-04-22 CVE-2016-4061 Improper Input Validation vulnerability in Foxitsoftware Foxit Reader and Phantompdf
Foxit Reader and PhantomPDF before 7.3.4 on Windows allow remote attackers to cause a denial of service (application crash) via a crafted content stream.
network
low complexity
foxitsoftware CWE-20
5.0
2016-04-22 CVE-2016-4060 Remote Code Execution vulnerability in Foxitsoftware Foxit Reader and Phantompdf
Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
network
low complexity
foxitsoftware
5.0
2016-04-22 CVE-2016-4059 Remote Code Execution vulnerability in Foxitsoftware Foxit Reader and Phantompdf
Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via a crafted FlateDecode stream in a PDF document.
network
foxitsoftware
6.8
2016-04-13 CVE-2015-8843 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Foxitsoftware Foxit Reader
The Foxit Cloud Update Service (FoxitCloudUpdateService) in Foxit Reader 6.1 through 6.2.x and 7.x before 7.2.2, when an update to the Cloud plugin is available, allows local users to gain privileges by writing crafted data to a shared memory region, which triggers memory corruption.
6.9
2015-12-16 CVE-2015-8580 Unspecified vulnerability in Foxitsoftware Foxit Reader and Phantompdf
Multiple use-after-free vulnerabilities in the (1) Print method and (2) App object handling in Foxit Reader before 7.2.2 and Foxit PhantomPDF before 7.2.2 allow remote attackers to execute arbitrary code via a crafted PDF document.
network
foxitsoftware
6.8
2015-05-01 CVE-2015-3633 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Foxitsoftware Enterprise Reader, Foxit Reader and Phantompdf
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via vectors related to digital signatures.
network
low complexity
foxitsoftware CWE-119
5.0
2015-05-01 CVE-2015-3632 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Foxitsoftware Enterprise Reader, Foxit Reader and Phantompdf
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted GIF in a PDF file.
4.3
2015-03-30 CVE-2015-2790 Improper Input Validation vulnerability in Foxitsoftware Enterprise Reader, Foxit Reader and Phantompdf
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted (1) Ubyte Size in a DataSubBlock structure or (2) LZWMinimumCodeSize in a GIF image.
4.3
2015-03-30 CVE-2015-2789 Local Privilege Escalation vulnerability in Foxit Reader
Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.1 through 7.0.6.1126 allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.
4.4
2014-10-17 CVE-2014-8074 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Foxitsoftware Foxit PDF SDK Activex
Buffer overflow in the SetLogFile method in Foxit.FoxitPDFSDKProCtrl.5 in Foxit PDF SDK ActiveX 2.3 through 5.0.1820 before 5.0.2.924 allows remote attackers to execute arbitrary code via a long string, related to global variables.
6.8