Vulnerabilities > Foxitsoftware > Phantompdf > 7.3.0.118

DATE CVE VULNERABILITY TITLE RISK
2016-10-31 CVE-2016-8875 Out-of-bounds Read vulnerability in Foxitsoftware Phantompdf and Reader
The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image, aka "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at ConvertToPDF_x86!CreateFXPDFConvertor."
network
high complexity
foxitsoftware CWE-125
5.3
2016-04-22 CVE-2016-4065 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Foxitsoftware Foxit Reader and Phantompdf
The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 7.3.4 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted (1) JPEG, (2) GIF, or (3) BMP image.
local
low complexity
foxitsoftware CWE-119
7.8
2016-04-22 CVE-2016-4064 Improper Access Control vulnerability in Foxitsoftware Foxit Reader and Phantompdf
Use-after-free vulnerability in the XFA forms handling functionality in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via a crafted remerge call.
local
low complexity
foxitsoftware CWE-284
7.8
2016-04-22 CVE-2016-4063 Unspecified vulnerability in Foxitsoftware Foxit Reader and Phantompdf
Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via an object with a revision number of -1 in a PDF document.
local
low complexity
foxitsoftware
7.8
2016-04-22 CVE-2016-4062 Data Processing Errors vulnerability in Foxitsoftware Foxit Reader and Phantompdf
Foxit Reader and PhantomPDF before 7.3.4 on Windows improperly report format errors recursively, which allows remote attackers to cause a denial of service (application hang) via a crafted PDF.
local
low complexity
foxitsoftware CWE-19
5.5
2016-04-22 CVE-2016-4061 Improper Input Validation vulnerability in Foxitsoftware Foxit Reader and Phantompdf
Foxit Reader and PhantomPDF before 7.3.4 on Windows allow remote attackers to cause a denial of service (application crash) via a crafted content stream.
network
low complexity
foxitsoftware CWE-20
7.5
2016-04-22 CVE-2016-4060 Unspecified vulnerability in Foxitsoftware Foxit Reader and Phantompdf
Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
network
low complexity
foxitsoftware
7.5
2016-04-22 CVE-2016-4059 Unspecified vulnerability in Foxitsoftware Foxit Reader and Phantompdf
Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via a crafted FlateDecode stream in a PDF document.
local
low complexity
foxitsoftware
7.8