Vulnerabilidades em Foxit

776 resultados
Análise Vexday

Com 776 CVEs catalogadas e nenhuma atualmente listada no catálogo KEV da CISA, o Foxit apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão imediata de ameaças confirmadas em campo. No entanto, o escore EPSS de 0,8948 associado a CVE-2021-34833 indica altíssima probabilidade estatística de exploração para essa vulnerabilidade específica, merecendo atenção prioritária mesmo na ausência de confirmação formal no KEV. O tipo de falha mais recorrente é CWE-416 (use-after-free), categoria historicamente propícia à execução de código arbitrário e frequentemente visada em leitores e editores de PDF. A existência de PoCs públicas para duas vulnerabilidades reforça a necessidade de manter patches aplicados, ainda que o volume de novas CVEs nos últimos 90 dias esteja zerado.

CVE-2022-37391HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.2.53575. User interaEPSS 1.0%CVE-2022-37378HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Editor 11.1.1.53537. User interaEPSS 1.0%CVE-2022-37384HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaEPSS 1.0%CVE-2022-37388HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.2.53575. User interaEPSS 1.0%CVE-2022-37390HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.2.53575. User interaEPSS 1.0%CVE-2022-37377HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Editor 11.1.1.53537;. User interEPSS 1.0%CVE-2022-40129HIGHA use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A specially-crafted PDFEPSS 1.0%CVE-2022-32774HIGHA use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely deletingEPSS 1.0%CVE-2022-43641LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 12.0.1.12430. UseEPSS 1.0%CVE-2022-28670LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. UseEPSS 1.0%CVE-2023-33876HIGHA use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15332 handles destroying annotations. Specially crafted Javascript codeEPSS 0.9%CVE-2022-43640LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 12.0.1.12430. UseEPSS 0.9%CVE-2013-10068CRITICALFoxit Reader <= 5.4.5.0114 Plugin URL Processing Buffer OverflowEPSS 0.9%CVE-2024-30331HIGHFoxit PDF Reader AcroForm Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-30332HIGHFoxit PDF Reader Doc Object Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-30328HIGHFoxit PDF Reader AcroForm Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-30325HIGHFoxit PDF Reader AcroForm Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-30334HIGHFoxit PDF Reader Doc Object Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-30324HIGHFoxit PDF Reader Doc Object Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-30326HIGHFoxit PDF Reader Doc Object Use-After-Free Remote Code Execution VulnerabilityEPSS 0.9%