Pdf Reader

Vendor:

First CVE: Apr 24, 2007 · Active for 19 years

346
Total CVEs
More Total CVEs than 100% of tracked products
43.3
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Pdf Reader over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 24, 2007
19 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

CVE Severity & Scoring

Pdf Reader346 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local290 (83.8%)
Network55 (15.9%)
Unknown1 (0.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low342 (98.8%)
High3 (0.9%)
Unknown1 (0.3%)
User Interaction
None19 (5.5%)
Unknown1 (0.3%)
Required324 (93.6%)
Privileges Required
Low11 (3.2%)
High0 (0.0%)
None334 (96.5%)
Unknown1 (0.3%)

Top CVEs

Signals from CVEs in this product scope (346 CVEs).

346 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulner
Aug 4, 20217.876NONO
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulner
Aug 4, 20217.858NONO
Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal
May 3, 20247.850NONO
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulner
Aug 4, 20217.844NONO
Foxit PDF Reader before 4.2.0.0928 does not properly bound-check the /Title entry in the PDF Info dictionary. A specially crafted PDF with an overlong Title string can overflow a f
Aug 20, 20258.442NOYES
The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT
Jul 8, 20267.837NONO
Foxit PDF Reader <  4.3.1.0218 exposes a JavaScript API function, createDataObject(), that allows untrusted PDF content to write arbitrary files anywhere on disk. By embedding a ma
Aug 20, 20258.436NOYES
Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpan="-2"' and 'draw colSpan="1"' substring
Feb 11, 20229.836NONO
When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old field pointers, resulting in invalid pointer references and cau
Jul 8, 20267.834NONO
After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the invalid object, which caused the application to crash.
Jul 8, 20267.834NONO

Exploit Exposure

Signals from CVEs in this product scope (346 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
0.6% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.3% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (346 CVEs).

Media Mentions

Signals from CVEs in this product scope (346 CVEs).

Top CNAs Publishing CVEs For Pdf Reader

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.0.1.104918.82.9%00
8.3.2.2501318.83.4%00
2025.1.0.2793718.80.6%00
2024.1.0.6368218.815.6%00
2024.1.0.2399748.812.7%00
2.015.07.6%01
12.1.2.1533248.61.0%00
12.1.1.1528918.80.9%00
12.0.1.1243047.81.0%00
11.1.0.5254328.83.2%00
11.0.0.4989318.81.9%00
10.1.4.3765118.81.9%00
10.1.3.3759818.84.5%00