Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55204
Total
4355
Critical
16406
High
16086
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-91817 | MEDIUM | 6.1 | A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded PDF JavaScript. Insufficient validation of string-deletion ranges can cause … | Sep 23, 2026 |
| CVE-2026-91816 | HIGH | 7.8 | A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations. Reentrant annotation deletion triggered by embedded JavaScript can cause the application to access … | Sep 23, 2026 |
| CVE-2026-91815 | HIGH | 7.8 | Foxit PDF Editor/Reader does not perform sufficient verification of the JPEG2000 image metadata in the PDF file, which leads to out-of-bounds write in the heap … | Sep 23, 2026 |
| CVE-2026-91814 | MEDIUM | 5.3 | A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of incrementally updated PDF documents. Changes to visible document content may not invalidate the existing … | Sep 23, 2026 |
| CVE-2026-91813 | HIGH | 8.8 | A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replaced between download and high-privilege extraction due to insufficient file locking … | Sep 23, 2026 |
| CVE-2026-91812 | HIGH | 7.9 | A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows man-in-the-middle attackers to bypass certificate validation and package integrity checks, potentially enabling arbitrary code execution with … | Sep 23, 2026 |
| CVE-2026-91811 | HIGH | 7.8 | A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s PRC parser due to insufficient validation of vertex indices in triangular fan texture meshes. Successful … | Sep 23, 2026 |
| CVE-2026-91810 | MEDIUM | 6.1 | A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF image masks. Inconsistent image metadata may cause incorrect alpha-channel processing during … | Sep 23, 2026 |
| CVE-2026-91809 | HIGH | 7.8 | A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF form fields. Improper validation during field-name traversal may cause the application to access … | Sep 23, 2026 |
| CVE-2026-91808 | MEDIUM | 6.1 | A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor Reader’s handling of PDF image objects with inconsistent compression metadata. Insufficient validation during image decoding … | Sep 23, 2026 |
| CVE-2026-91807 | MEDIUM | 6.1 | A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed image soft-mask data. Insufficient validation of the soft-mask data attribute during image … | Sep 23, 2026 |
| CVE-2026-91806 | HIGH | 7.8 | A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF form fields. Embedded JavaScript may access form-field references after the corresponding fields have been … | Sep 23, 2026 |
| CVE-2026-91805 | HIGH | 7.8 | A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s PDF page-tree handling. A specially crafted PDF can trigger page-structure changes during rendering, causing the application to … | Sep 23, 2026 |
| CVE-2026-91804 | HIGH | 7.8 | A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s rendering of Circle annotations with malformed Cloudy appearance streams in specially crafted PDF files. Insufficient … | Sep 23, 2026 |
| CVE-2026-91803 | HIGH | 8.8 | A local privilege escalation vulnerability exists in the updater of Foxit PDF Editor/Reader due to unsafe loading of dynamic-link libraries from a user-writable directory during … | Sep 23, 2026 |
| CVE-2026-91802 | HIGH | 7.8 | A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s WebP image decoding due to improper handling of bitmap stride and target buffer formats. Successful … | Sep 23, 2026 |
| CVE-2026-91801 | HIGH | 7.8 | A path traversal vulnerability exists in Foxit PDF Editor/Reader's handling of embedded PDF resources. Insufficient validation of resource file paths may allow files to be … | Sep 23, 2026 |
| CVE-2026-91800 | HIGH | 8.8 | A local privilege escalation vulnerability exists in the installer of Foxit PDF Editor for macOS due to insufficient validation of a user-modifiable configuration value during … | Sep 23, 2026 |
| CVE-2026-91799 | HIGH | 7.8 | A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of JavaScript array objects. A specially crafted PDF may cause the application to access a released … | Sep 23, 2026 |
| CVE-2026-91798 | HIGH | 8.8 | A local privilege escalation vulnerability exists in the update daemon of Foxit PDF Editor/Reader due to an insecure permission configuration that allows the configuration file … | Sep 23, 2026 |
| CVE-2026-91797 | HIGH | 7.8 | Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to be written to … | Sep 23, 2026 |
| CVE-2026-91796 | MEDIUM | 6.1 | The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without … | Sep 23, 2026 |
| CVE-2026-91795 | HIGH | 7.8 | Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files. This could leave an internal pointer in an … | Sep 23, 2026 |
| CVE-2026-91794 | HIGH | 7.8 | An out-of-bounds write vulnerability exists in the PDF rendering process of Foxit PDF Editor/Reader due to insufficient consistency and boundary validation when processing malformed color … | Sep 23, 2026 |
| CVE-2026-91793 | HIGH | 7.8 | When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attributes containing malformed font data. During subsequent annotation appearance reconstruction, … | Sep 23, 2026 |