Reader

Vendor:

First CVE: Apr 25, 2008 · Active for 18 years

261
Total CVEs
Bottom 1%
32.6
Avg CVEs / Year
Bottom 1%
8.1
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Reader over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 25, 2008
18 years ago
Most Recent CVE
Jul 20, 2021
1,830 days ago

CVE Severity & Scoring

Reader261 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local82 (31.4%)
Network177 (67.8%)
Unknown2 (0.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low249 (95.4%)
High10 (3.8%)
Unknown2 (0.8%)
User Interaction
None40 (15.3%)
Unknown2 (0.8%)
Required219 (83.9%)
Privileges Required
Low2 (0.8%)
High0 (0.0%)
None257 (98.5%)
Unknown2 (0.8%)

Top CVEs

Signals from CVEs in this product scope (261 CVEs).

261 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing dangerous actions defined in a PDF file,
Mar 10, 200910.062NOYES
An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Software's PDF Reader version 9.1.0.5096. A specially crafted PDF
Jan 30, 20197.149NONO
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.6.0.25114. User interaction is required to exploit this vulnerabili
Feb 14, 20207.837NONO
This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25608. User interaction is required to exploit this vulnerab
Feb 14, 20207.835NONO
This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerab
Feb 14, 20207.835NONO
This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerab
Feb 14, 20207.832NONO
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vu
Jan 24, 20196.532NONO
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are m
Sep 28, 20189.832NONO
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It has a use-after-free via a document that lacks a dictionary.
Jun 4, 20209.831NONO
An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has an out-of-bounds write when Internet Explorer is used.
Jun 4, 20209.830NONO

Exploit Exposure

Signals from CVEs in this product scope (261 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.4% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (261 CVEs).

Media Mentions

Signals from CVEs in this product scope (261 CVEs).

Top CNAs Publishing CVEs For Reader

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.0.2.80513.318.6%00
3.0110.040.9%01
2.3110.040.9%01
2.216.84.1%00