Vulnerabilities > Foxitsoftware > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2015-05-01 | CVE-2015-3633 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Foxitsoftware Enterprise Reader, Foxit Reader and Phantompdf Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via vectors related to digital signatures. | 5.0 |
2015-05-01 | CVE-2015-3632 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Foxitsoftware Enterprise Reader, Foxit Reader and Phantompdf Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted GIF in a PDF file. | 4.3 |
2015-03-30 | CVE-2015-2790 | Improper Input Validation vulnerability in Foxitsoftware Enterprise Reader, Foxit Reader and Phantompdf Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted (1) Ubyte Size in a DataSubBlock structure or (2) LZWMinimumCodeSize in a GIF image. | 4.3 |
2015-03-30 | CVE-2015-2789 | Local Privilege Escalation vulnerability in Foxit Reader Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.1 through 7.0.6.1126 allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder. local foxitsoftware | 4.4 |
2014-10-17 | CVE-2014-8074 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Foxitsoftware Foxit PDF SDK Activex Buffer overflow in the SetLogFile method in Foxit.FoxitPDFSDKProCtrl.5 in Foxit PDF SDK ActiveX 2.3 through 5.0.1820 before 5.0.2.924 allows remote attackers to execute arbitrary code via a long string, related to global variables. | 6.8 |
2014-10-01 | CVE-2014-6853 | Cryptographic Issues vulnerability in Foxitsoftware Foxit Mobilepdf - PDF Reader 2.2.0.0616 The Foxit MobilePDF - PDF Reader (aka com.foxit.mobile.pdf.lite) application 2.2.0.0616 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 5.4 |
2014-07-07 | CVE-2014-4646 | Buffer Errors vulnerability in Foxitsoftware Foxit PDF SDK DLL 3.1.1.2927 Buffer overflow in the FPDFBookmark_GetTitle method in Foxit PDF SDK DLL before 3.1.1.5005 allows context-dependent attackers to execute arbitrary code via unspecified vectors. | 6.8 |
2012-09-06 | CVE-2012-4759 | Unspecified vulnerability in Foxitsoftware Foxit Reader 5.3.1.0606 Untrusted search path vulnerability in facebook_plugin.fpi in the Facebook plug-in in Foxit Reader 5.3.1.0606 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .pdf file. local foxitsoftware | 6.9 |