Risk | High |
Patch available | YES |
Number of vulnerabilities | 14 |
CVE-ID | CVE-2018-3924 CVE-2018-3939 CVE-2018-14442 |
CWE-ID | CWE-416 CWE-787 CWE-125 CWE-843 CWE-20 CWE-200 CWE-122 CWE-190 CWE-120 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
Foxit PDF Reader for Windows Client/Desktop applications / Office applications Foxit PDF Editor (formerly Foxit PhantomPDF) Client/Desktop applications / Office applications |
Vendor | Foxit Software Inc. |
This security bulletin contains information about 14 vulnerabilities.
EUVDB-ID: #VU13956
Risk: High
CVSSv3.1:
CVE-ID: CVE-2018-3924
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionUpdate to version 9.2.
Foxit PDF Reader for Windows: 9.0 - 9.1.0.5096
Foxit PDF Editor (formerly Foxit PhantomPDF): 9.0 - 9.1.0.5096
http://www.foxitsoftware.com/support/security-bulletins.php
Can this vulnerability be exploited remotely?
How the attacker can exploit this vulnerability?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU13957
Risk: High
CVSSv3.1:
CVE-ID: CVE-2018-3939
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionUpdate to version 9.2.
Foxit PDF Reader for Windows: 9.0 - 9.1.0.5096
Foxit PDF Editor (formerly Foxit PhantomPDF): 9.0 - 9.1.0.5096
http://www.foxitsoftware.com/support/security-bulletins.php
Can this vulnerability be exploited remotely?
How the attacker can exploit this vulnerability?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU13958
Risk: High
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-787 - Out-of-bounds write
Exploit availability: No
DescriptionUpdate to version 9.2.
Foxit PDF Reader for Windows: 9.0 - 9.1.0.5096
Foxit PDF Editor (formerly Foxit PhantomPDF): 9.0 - 9.1.0.5096
http://www.foxitsoftware.com/support/security-bulletins.php
Can this vulnerability be exploited remotely?
How the attacker can exploit this vulnerability?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU13959
Risk: High
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-843 - Access of Resource Using Incompatible Type ('Type Confusion')
Exploit availability: No
DescriptionUpdate to version 9.2.
Foxit PDF Reader for Windows: 9.0 - 9.1.0.5096
Foxit PDF Editor (formerly Foxit PhantomPDF): 9.0 - 9.1.0.5096
http://www.foxitsoftware.com/support/security-bulletins.php
Can this vulnerability be exploited remotely?
How the attacker can exploit this vulnerability?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU13960
Risk: High
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-843 - Access of Resource Using Incompatible Type ('Type Confusion')
Exploit availability: No
DescriptionUpdate to version 9.2.
Foxit PDF Reader for Windows: 9.0 - 9.1.0.5096
Foxit PDF Editor (formerly Foxit PhantomPDF): 9.0 - 9.1.0.5096
http://www.foxitsoftware.com/support/security-bulletins.php
Can this vulnerability be exploited remotely?
How the attacker can exploit this vulnerability?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU13961
Risk: High
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-843 - Access of Resource Using Incompatible Type ('Type Confusion')
Exploit availability: No
DescriptionUpdate to version 9.2.
Foxit PDF Reader for Windows: 9.0 - 9.1.0.5096
Foxit PDF Editor (formerly Foxit PhantomPDF): 9.0 - 9.1.0.5096
http://www.foxitsoftware.com/support/security-bulletins.php
Can this vulnerability be exploited remotely?
How the attacker can exploit this vulnerability?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU13962
Risk: High
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionUpdate to version 9.2.
Foxit PDF Reader for Windows: 9.0 - 9.1.0.5096
Foxit PDF Editor (formerly Foxit PhantomPDF): 9.0 - 9.1.0.5096
http://www.foxitsoftware.com/support/security-bulletins.php
Can this vulnerability be exploited remotely?
How the attacker can exploit this vulnerability?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU13963
Risk: Low
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionUpdate to version 9.2.
Foxit PDF Reader for Windows: 9.0 - 9.1.0.5096
Foxit PDF Editor (formerly Foxit PhantomPDF): 9.0 - 9.1.0.5096
http://www.foxitsoftware.com/support/security-bulletins.php
Can this vulnerability be exploited remotely?
How the attacker can exploit this vulnerability?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU13964
Risk: High
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-122 - Heap-based Buffer Overflow
Exploit availability: No
DescriptionUpdate to version 9.2.
Foxit PDF Reader for Windows: 9.0 - 9.1.0.5096
Foxit PDF Editor (formerly Foxit PhantomPDF): 9.0 - 9.1.0.5096
http://www.foxitsoftware.com/support/security-bulletins.php
Can this vulnerability be exploited remotely?
How the attacker can exploit this vulnerability?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU13965
Risk: High
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-190 - Integer overflow
Exploit availability: No
DescriptionUpdate to version 9.2.
Foxit PDF Reader for Windows: 9.0 - 9.1.0.5096
Foxit PDF Editor (formerly Foxit PhantomPDF): 9.0 - 9.1.0.5096
http://www.foxitsoftware.com/support/security-bulletins.php
Can this vulnerability be exploited remotely?
How the attacker can exploit this vulnerability?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU13966
Risk: High
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-843 - Access of Resource Using Incompatible Type ('Type Confusion')
Exploit availability: No
DescriptionUpdate to version 9.2.
Foxit PDF Reader for Windows: 9.0 - 9.1.0.5096
Foxit PDF Editor (formerly Foxit PhantomPDF): 9.0 - 9.1.0.5096
http://www.foxitsoftware.com/support/security-bulletins.php
Can this vulnerability be exploited remotely?
How the attacker can exploit this vulnerability?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU13967
Risk: Low
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionUpdate to version 9.2.
Foxit PDF Reader for Windows: 9.0 - 9.1.0.5096
Foxit PDF Editor (formerly Foxit PhantomPDF): 9.0 - 9.1.0.5096
http://www.foxitsoftware.com/support/security-bulletins.php
Can this vulnerability be exploited remotely?
How the attacker can exploit this vulnerability?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU13968
Risk: Low
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-120 - Buffer overflow
Exploit availability: No
DescriptionUpdate to version 9.2.
Foxit PDF Reader for Windows: 9.0 - 9.1.0.5096
Foxit PDF Editor (formerly Foxit PhantomPDF): 9.0 - 9.1.0.5096
http://www.foxitsoftware.com/support/security-bulletins.php
Can this vulnerability be exploited remotely?
How the attacker can exploit this vulnerability?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU14117
Risk: High
CVSSv3.1:
CVE-ID: CVE-2018-14442
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionUpdate to version 9.2.
Foxit PDF Reader for Windows: 9.0 - 9.1.0.5096
Foxit PDF Editor (formerly Foxit PhantomPDF): 9.0 - 9.1.0.5096
http://www.foxitsoftware.com/support/security-bulletins.php
Can this vulnerability be exploited remotely?
How the attacker can exploit this vulnerability?
Is there known malware, which exploits this vulnerability?