Foxit Reader

Vendor:

First CVE: May 21, 2008 · Active for 18 years

372
Total CVEs
More Total CVEs than 100% of tracked products
26.6
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 68% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Foxit Reader over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 21, 2008
18 years ago
Most Recent CVE
Nov 27, 2023
970 days ago

CVE Severity & Scoring

Foxit Reader372 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local95 (25.5%)
Network262 (70.4%)
Unknown15 (4.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low355 (95.4%)
High2 (0.5%)
Unknown15 (4.0%)
User Interaction
None26 (7.0%)
Unknown15 (4.0%)
Required331 (89.0%)
Privileges Required
Low5 (1.3%)
High0 (0.0%)
None352 (94.6%)
Unknown15 (4.0%)

Top CVEs

Signals from CVEs in this product scope (372 CVEs).

372 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerabil
May 17, 20188.879NOYES
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this v
May 17, 20186.575NOYES
A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of pre
Dec 22, 20208.860NONO
In Foxit Reader 10.1.0.37527, a specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution. An attacker needs to trick th
Feb 10, 20218.857NONO
Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. An attacker can execute local files and bypass the security dialog.
Nov 2, 20207.850NOYES
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.5096. A specially crafted PDF document can trigger a pr
Aug 1, 20187.849NONO
Foxit Reader before 3.2.1.0401 allows remote attackers to (1) execute arbitrary local programs via a certain "/Type /Action /S /Launch" sequence, and (2) execute arbitrary programs
Apr 5, 20109.340NOYES
An exploitable type confusion vulnerability exists in the way Foxit PDF Reader version 9.0.1.1049 parses files with associated file annotations. A specially crafted PDF document ca
Apr 19, 20188.839NONO
Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs.
Jul 20, 20189.833NONO
Heap-based buffer overflow in the CreateFXPDFConvertor function in ConvertToPdf_x86.dll in Foxit Reader 7.3.4.311 allows remote attackers to execute arbitrary code via a large Samp
Apr 4, 20177.833NONO

Exploit Exposure

Signals from CVEs in this product scope (372 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
0.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
1.9% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (372 CVEs).

Media Mentions

Signals from CVEs in this product scope (372 CVEs).

Top CNAs Publishing CVEs For Foxit Reader

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.415.31.1%00
9.3.0.10826136.82.1%00
9.2.0.929715.33.7%00
9.2.025.32.4%00
9.1.025.32.7%00
9.0.1.104938.810.2%00
9.0.1.10416.52.9%00
9.0.0.2993516.52.5%00
8.3.2.25013118.13.0%00
8.3.1.21155328.12.6%00
8.3.118.82.6%00
8.3.0.1487877.82.8%00
8.2.1.687138.82.8%00
8.2.0.205118.87.1%00
8.1.4.120818.13.8%00
7.3.4.31117.815.8%00
7.217.40.7%00
7.1.517.40.7%00
7.1.0.30615.02.7%00
7.0.625.91.9%01