Known vulnerabilities in Foxit PDF Editor for Mac (formerly PhantomPDF)

Software CPE: cpe:2.3:a:foxit_software:foxit_phantompdf_for_mac:*:*:*:*:*:*:*:*
Total vulnerabilities: 37
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Foxit PDF Editor for Mac (formerly PhantomPDF) Foxit PDF Editor for Mac (formerly PhantomPDF) is affected by 37 known vulnerabilities: 20 high, 3 medium, 14 low Critical High Medium Low

Vulnerabilities (37)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU124715 - NULL Pointer Dereference
CVE-2026-3776
CWE-476 Low
No
No
13.2.3.63444, 14.0.3.69295, 2026.1.0.70169 31.03.2026 SB2026033195
SB2026040147
#VU124716 - Use After Free
CVE-2026-3777
CWE-416 High
No
No
13.2.3.63444, 14.0.3.69295, 2026.1.0.70169 31.03.2026 SB2026033195
SB2026040147
#VU124717 - Use After Free
CVE-2026-3779
CWE-416 High
No
No
13.2.3.63444, 14.0.3.69295, 2026.1.0.70169 31.03.2026 SB2026033195
SB2026040147
#VU124718 - Uncontrolled Recursion
CVE-2026-3778
CWE-674 Low
No
No
13.2.3.63444, 14.0.3.69295, 2026.1.0.70169 31.03.2026 SB2026033195
SB2026040147
#VU101824 - Exposure of sensitive information to an unauthorized actor
CWE-200 Medium
No
No
11.1.11.1202, 12.1.7.55606, 13.1.5.63001, 2024.4.0.66473 18.12.2024 SB2024121815
SB2024121831
#VU101823 - Improper Verification of Cryptographic Signature
CWE-347 Low
No
No
11.1.11.1202, 12.1.7.55606, 13.1.5.63001, 2024.4.0.66473 18.12.2024 SB2024121815
SB2024121831
#VU101822 - Improper Authorization in Handler for Custom URL Scheme
CWE-939 High
No
No
11.1.11.1202, 12.1.7.55606, 13.1.5.63001, 2024.4.0.66473 18.12.2024 SB2024121815
SB2024121831
#VU97911 - Incorrect Default Permissions
CWE-276 Low
No
No
13.1.4.62748, 2024.3.0.65538 01.10.2024 SB2024100138
#VU97898 - Use After Free
CVE-2024-7725
CWE-416 High
No
No
11.1.10.1010, 12.1.6.55574, 13.1.4.62748, 2024.3.0.65538 01.10.2024 SB2024100116
SB2024100138
#VU97878 - Use After Free
CVE-2024-28888
CWE-416 High
No
No
11.1.10.1010, 12.1.6.55574, 13.1.4.62748, 2024.3.0.65538 01.10.2024 SB2024100116
SB2024100138
#VU97880 - Use After Free
CVE-2024-9243
CWE-416 High
No
No
13.1.4.62748, 2024.3.0.65538 01.10.2024 SB2024100116
SB2024100138
#VU97886 - Use After Free
CVE-2024-9254
CWE-416 High
No
No
11.1.10.1010, 12.1.6.55574, 13.1.4.62748, 2024.3.0.65538 01.10.2024 SB2024100116
SB2024100138
#VU89812 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-78 Medium
No
No
2024.2.2.64388 24.05.2024 SB2024052464
#VU87287 - NULL Pointer Dereference
CWE-476 Low
No
No
2024.1.0.63682 08.03.2024 SB2024030814
SB2024030826
#VU87285 - Use After Free
CVE-2024-30322
CWE-416 High
No
No
2024.1.0.63682 08.03.2024 SB2024030814
SB2024030826
#VU87284 - Out-of-bounds read
CVE-2024-30323
CWE-125 High
No
No
2024.1.0.63682 08.03.2024 SB2024030814
SB2024030826
#VU85616 - Memory corruption
CVE-2023-51562
CWE-119 High
No
No
11.1.6.0109, 12.1.2.55366 19.01.2024 SB2024011921
SB2024012216
#VU85615 - Memory corruption
CVE-2023-51550
CWE-119 High
No
No
11.1.6.0109, 12.1.2.55366 19.01.2024 SB2024011921
SB2024012216
#VU85614 - Memory corruption
CVE-2023-42089
CWE-119 High
No
No
11.1.6.0109, 12.1.2.55366 19.01.2024 SB2024011921
SB2024012216
#VU85613 - Memory corruption
CVE-2023-51551
CWE-119 High
No
No
11.1.6.0109, 12.1.2.55366 19.01.2024 SB2024011921
SB2024012216


Showing elements 1 - 20 out of 37