Reader
Vendor:
First CVE: Apr 25, 2008 · Active for 18 years
261
Total CVEs
Bottom 1%
32.6
Avg CVEs / Year
Bottom 1%
8.1
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Reader over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 25, 2008
18 years ago
Most Recent CVE
Jul 20, 2021
1,830 days ago
CVE Severity & Scoring
Reader261 CVEs
88%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local82 (31.4%)
Network177 (67.8%)
Unknown2 (0.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low249 (95.4%)
High10 (3.8%)
Unknown2 (0.8%)
User Interaction
None40 (15.3%)
Unknown2 (0.8%)
Required219 (83.9%)
Privileges Required
Low2 (0.8%)
High0 (0.0%)
None257 (98.5%)
Unknown2 (0.8%)
Top CVEs
Signals from CVEs in this product scope (261 CVEs).
261 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-0836HIGH Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing dangerous actions defined in a PDF file, | Mar 10, 2009 | 10.0 | 62 | NO | YES |
CVE-2018-3956HIGH An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Software's PDF Reader version 9.1.0.5096. A specially crafted PDF | Jan 30, 2019 | 7.1 | 49 | NO | NO |
CVE-2020-8844HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.6.0.25114. User interaction is required to exploit this vulnerabili | Feb 14, 2020 | 7.8 | 37 | NO | NO |
CVE-2020-8856HIGH This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25608. User interaction is required to exploit this vulnerab | Feb 14, 2020 | 7.8 | 35 | NO | NO |
CVE-2020-8846HIGH This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerab | Feb 14, 2020 | 7.8 | 35 | NO | NO |
CVE-2020-8845HIGH This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerab | Feb 14, 2020 | 7.8 | 32 | NO | NO |
CVE-2018-17686MEDIUM This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vu | Jan 24, 2019 | 6.5 | 32 | NO | NO |
CVE-2018-17607CRITICAL Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are m | Sep 28, 2018 | 9.8 | 32 | NO | NO |
CVE-2020-13814CRITICAL An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It has a use-after-free via a document that lacks a dictionary. | Jun 4, 2020 | 9.8 | 31 | NO | NO |
CVE-2019-20830CRITICAL An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has an out-of-bounds write when Internet Explorer is used. | Jun 4, 2020 | 9.8 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (261 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.4% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (261 CVEs).
Media Mentions
Signals from CVEs in this product scope (261 CVEs).
Top CNAs Publishing CVEs For Reader
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.0.2.805 | 1 | 3.3 | 18.6% | 0 | 0 |
| 3.0 | 1 | 10.0 | 40.9% | 0 | 1 |
| 2.3 | 1 | 10.0 | 40.9% | 0 | 1 |
| 2.2 | 1 | 6.8 | 4.1% | 0 | 0 |