Foxit Software develops a narrowly scoped but globally distributed portfolio of PDF-handling tools—readers, editors, and cloud-based signing platforms—whose ubiquity in enterprise and consumer workflows creates a significant downstream footprint despite the small product count. The vendor's vulnerability surface is heavily represented in the landscape and recurs persistently through memory-safety weaknesses including use-after-free conditions, out-of-bounds reads and writes, and NULL-pointer dereferences that are endemic to PDF parsing, plus application-layer input-validation issues such as cross-site scripting in web-facing signing interfaces. Defenders should treat Foxit advisories as broadly applicable given the prevalence of the affected products in document workflows and the parser-complexity class of the recurring flaws; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Foxit Software Incorporated over time
Of all the CVEs published by Foxit Software Incorporated as a CNA, 100.0% affect products that Foxit Software Incorporated develops as a vendor.
Of all the CVEs published that affect products developed by Foxit Software Incorporated, 17.6% are self-published by Foxit Software Incorporated as a CNA.
Signals from CVEs in this vendor scope (1136 CVEs).
1,136 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-0837HIGH Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to execute arbitrary code via a long (1) relative path or (2) ab | Mar 10, 2009 | 10.0 | 84 | NO | YES |
CVE-2018-9958HIGH This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerabil | May 17, 2018 | 8.8 | 79 | NO | YES |
CVE-2021-34833HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulner | Aug 4, 2021 | 7.8 | 76 | NO | NO |
CVE-2018-9948MEDIUM This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this v | May 17, 2018 | 6.5 | 75 | NO | YES |
CVE-2009-0836HIGH Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing dangerous actions defined in a PDF file, | Mar 10, 2009 | 10.0 | 62 | NO | YES |
CVE-2020-13557HIGH A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of pre | Dec 22, 2020 | 8.8 | 60 | NO | NO |
CVE-2021-34847HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulner | Aug 4, 2021 | 7.8 | 58 | NO | NO |
CVE-2020-13548HIGH In Foxit Reader 10.1.0.37527, a specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution. An attacker needs to trick th | Feb 10, 2021 | 8.8 | 57 | NO | NO |
CVE-2018-20247HIGH In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree structure using the LoadFromFile, LoadFr | Dec 24, 2018 | 7.8 | 53 | NO | NO |
CVE-2023-27363HIGH Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal | May 3, 2024 | 7.8 | 50 | NO | NO |
Signals from CVEs in this vendor scope (1136 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Foxit Software Incorporated.
Media articles that mention a CVE ID that affects a product developed by Foxit Software Incorporated — matched by CVE ID, not by vendor name.