Vulnerabilities in Foxit

776 results
Vexday analysis

Com 776 CVEs catalogadas e nenhuma atualmente listada no catálogo KEV da CISA, o Foxit apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão imediata de ameaças confirmadas em campo. No entanto, o escore EPSS de 0,8948 associado a CVE-2021-34833 indica altíssima probabilidade estatística de exploração para essa vulnerabilidade específica, merecendo atenção prioritária mesmo na ausência de confirmação formal no KEV. O tipo de falha mais recorrente é CWE-416 (use-after-free), categoria historicamente propícia à execução de código arbitrário e frequentemente visada em leitores e editores de PDF. A existência de PoCs públicas para duas vulnerabilidades reforça a necessidade de manter patches aplicados, ainda que o volume de novas CVEs nos últimos 90 dias esteja zerado.

CVE-2025-32451HIGHA memory corruption vulnerability exists in Foxit Reader 2025.1.0.27937 due to the use of an uninitialized pointer. A specially crafted JavaEPSS 0.5%CVE-2023-27366HIGHFoxit PDF Reader Doc Object Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-27364HIGHFoxit PDF Editor XLS File Parsing Exposed Dangerous Method Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-27365HIGHFoxit PDF Editor DOC File Parsing Exposed Dangerous Method Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-9246LOWFoxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-30340LOWFoxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-30350LOWFoxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-30356LOWFoxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-29072HIGHA privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validEPSS 0.5%CVE-2023-42089LOWFoxit PDF Reader templates Use-After-Free Information Disclosure VulnerabilityEPSS 0.5%CVE-2023-42091HIGHFoxit PDF Reader XFA Doc Object Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-42092HIGHFoxit PDF Reader Doc Object Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-42094HIGHFoxit PDF Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-42097HIGHFoxit PDF Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-42096HIGHFoxit PDF Reader PDF File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-38112HIGHFoxit PDF Reader XFA Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-38117HIGHFoxit PDF Reader AcroForm Doc Object Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-38107HIGHFoxit PDF Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-38111HIGHFoxit PDF Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-9251LOWFoxit PDF Reader Annotation Use-After-Free Information Disclosure VulnerabilityEPSS 0.4%