Foxit Reader
Vendor:
First CVE: May 21, 2008 · Active for 18 years
372
Total CVEs
More Total CVEs than 100% of tracked products
26.6
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 68% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Foxit Reader over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 21, 2008
18 years ago
Most Recent CVE
Nov 27, 2023
970 days ago
CVE Severity & Scoring
Foxit Reader372 CVEs
20%
73%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local95 (25.5%)
Network262 (70.4%)
Unknown15 (4.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low355 (95.4%)
High2 (0.5%)
Unknown15 (4.0%)
User Interaction
None26 (7.0%)
Unknown15 (4.0%)
Required331 (89.0%)
Privileges Required
Low5 (1.3%)
High0 (0.0%)
None352 (94.6%)
Unknown15 (4.0%)
Top CVEs
Signals from CVEs in this product scope (372 CVEs).
372 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-9958HIGH This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerabil | May 17, 2018 | 8.8 | 79 | NO | YES |
CVE-2018-9948MEDIUM This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this v | May 17, 2018 | 6.5 | 75 | NO | YES |
CVE-2020-13557HIGH A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of pre | Dec 22, 2020 | 8.8 | 60 | NO | NO |
CVE-2020-13548HIGH In Foxit Reader 10.1.0.37527, a specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution. An attacker needs to trick th | Feb 10, 2021 | 8.8 | 57 | NO | NO |
CVE-2020-14425HIGH Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. An attacker can execute local files and bypass the security dialog. | Nov 2, 2020 | 7.8 | 50 | NO | YES |
CVE-2018-3924HIGH An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.5096. A specially crafted PDF document can trigger a pr | Aug 1, 2018 | 7.8 | 49 | NO | NO |
CVE-2010-1239HIGH Foxit Reader before 3.2.1.0401 allows remote attackers to (1) execute arbitrary local programs via a certain "/Type /Action /S /Launch" sequence, and (2) execute arbitrary programs | Apr 5, 2010 | 9.3 | 40 | NO | YES |
CVE-2018-3843HIGH An exploitable type confusion vulnerability exists in the way Foxit PDF Reader version 9.0.1.1049 parses files with associated file annotations. A specially crafted PDF document ca | Apr 19, 2018 | 8.8 | 39 | NO | NO |
CVE-2018-14442CRITICAL Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs. | Jul 20, 2018 | 9.8 | 33 | NO | NO |
CVE-2016-3740HIGH Heap-based buffer overflow in the CreateFXPDFConvertor function in ConvertToPdf_x86.dll in Foxit Reader 7.3.4.311 allows remote attackers to execute arbitrary code via a large Samp | Apr 4, 2017 | 7.8 | 33 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (372 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
0.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
1.9% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (372 CVEs).
Media Mentions
Signals from CVEs in this product scope (372 CVEs).
Top CNAs Publishing CVEs For Foxit Reader
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.4 | 1 | 5.3 | 1.1% | 0 | 0 |
| 9.3.0.10826 | 13 | 6.8 | 2.1% | 0 | 0 |
| 9.2.0.9297 | 1 | 5.3 | 3.7% | 0 | 0 |
| 9.2.0 | 2 | 5.3 | 2.4% | 0 | 0 |
| 9.1.0 | 2 | 5.3 | 2.7% | 0 | 0 |
| 9.0.1.1049 | 3 | 8.8 | 10.2% | 0 | 0 |
| 9.0.1.104 | 1 | 6.5 | 2.9% | 0 | 0 |
| 9.0.0.29935 | 1 | 6.5 | 2.5% | 0 | 0 |
| 8.3.2.25013 | 11 | 8.1 | 3.0% | 0 | 0 |
| 8.3.1.21155 | 32 | 8.1 | 2.6% | 0 | 0 |
| 8.3.1 | 1 | 8.8 | 2.6% | 0 | 0 |
| 8.3.0.14878 | 7 | 7.8 | 2.8% | 0 | 0 |
| 8.2.1.6871 | 3 | 8.8 | 2.8% | 0 | 0 |
| 8.2.0.2051 | 1 | 8.8 | 7.1% | 0 | 0 |
| 8.1.4.1208 | 1 | 8.1 | 3.8% | 0 | 0 |
| 7.3.4.311 | 1 | 7.8 | 15.8% | 0 | 0 |
| 7.2 | 1 | 7.4 | 0.7% | 0 | 0 |
| 7.1.5 | 1 | 7.4 | 0.7% | 0 | 0 |
| 7.1.0.306 | 1 | 5.0 | 2.7% | 0 | 0 |
| 7.0.6 | 2 | 5.9 | 1.9% | 0 | 1 |