Known vulnerabilities in Foxit PDF Editor for Mac (formerly PhantomPDF)
Vendor:
Foxit Software Inc.
Software CPE:
cpe:2.3:a:foxit_software:foxit_phantompdf_for_mac:*:*:*:*:*:*:*:*
Website:
https://www.foxitsoftware.com/
Total vulnerabilities:
37
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
13.1.6.63007
13.1.7.63027
13.2.0.63256
13.2.1.63315
13.2.2.63349
13.2.3.63444
14.0.0.68868
14.0.1.69005
14.0.2.69164
14.0.3.69295
2026.1.0.70169
2024.4.1.66479
2025.1.0.66692
2025.2.0.68868
2025.2.1.69005
2025.3.0.69570
11.1.11.1202
12.1.7.55606
13.1.5.63001
2024.4.0.66473
12.1.6.55574
11.1.10.1010
2024.2.0.64371
2024.2.1.64379
2024.2.3.64402
2024.3.0.65538
11.1.7.0418
11.1.8.0513
11.1.9.0524
12.1.3.55436
12.1.4.55444
12.1.5.55449
13.1.0.62175
13.1.1.62190
13.1.2.62201
13.1.4.62748
2024.2.2.64388
2024.1.0.63682
12.1.2.55366
11.1.6.0109
11.1.5.0913
2023.3.0.63083
2023.2.0.61611
2023.1.0.55583
13.0.1.61866
13.0.0.61829
12.1.1.55342
12.1.0.1229
11.1.1.0126
11.0.0.0510
11.1.2.0420
11.1.4.1121
12.0.2.1028
11.1.3.0920
12.0.0.0601
12.0.1.0720
11.1.1.0119
11.1.0.0925
11.0.1.0719
11.0.1.0917
4.1.0.0926
4.1.3.0129
4.1.1.1123
4.0.0.0430
3.4.0.1012
3.3.0.0709
3.2.0.0404
3.1.0.0111
3.0.1.1116
3.0.0.0818
Vulnerabilities (37)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU124715 - NULL Pointer Dereference CVE-2026-3776 |
CWE-476 | Low | 13.2.3.63444, 14.0.3.69295, 2026.1.0.70169 | 31.03.2026 |
SB2026033195 SB2026040147 |
||
| #VU124716 - Use After Free CVE-2026-3777 |
CWE-416 | High | 13.2.3.63444, 14.0.3.69295, 2026.1.0.70169 | 31.03.2026 |
SB2026033195 SB2026040147 |
||
| #VU124717 - Use After Free CVE-2026-3779 |
CWE-416 | High | 13.2.3.63444, 14.0.3.69295, 2026.1.0.70169 | 31.03.2026 |
SB2026033195 SB2026040147 |
||
| #VU124718 - Uncontrolled Recursion CVE-2026-3778 |
CWE-674 | Low | 13.2.3.63444, 14.0.3.69295, 2026.1.0.70169 | 31.03.2026 |
SB2026033195 SB2026040147 |
||
| #VU101824 - Exposure of sensitive information to an unauthorized actor |
CWE-200 | Medium | 11.1.11.1202, 12.1.7.55606, 13.1.5.63001, 2024.4.0.66473 | 18.12.2024 |
SB2024121815 SB2024121831 |
||
| #VU101823 - Improper Verification of Cryptographic Signature |
CWE-347 | Low | 11.1.11.1202, 12.1.7.55606, 13.1.5.63001, 2024.4.0.66473 | 18.12.2024 |
SB2024121815 SB2024121831 |
||
| #VU101822 - Improper Authorization in Handler for Custom URL Scheme |
CWE-939 | High | 11.1.11.1202, 12.1.7.55606, 13.1.5.63001, 2024.4.0.66473 | 18.12.2024 |
SB2024121815 SB2024121831 |
||
| #VU97911 - Incorrect Default Permissions |
CWE-276 | Low | 13.1.4.62748, 2024.3.0.65538 | 01.10.2024 |
SB2024100138 |
||
| #VU97898 - Use After Free CVE-2024-7725 |
CWE-416 | High | 11.1.10.1010, 12.1.6.55574, 13.1.4.62748, 2024.3.0.65538 | 01.10.2024 |
SB2024100116 SB2024100138 |
||
| #VU97878 - Use After Free CVE-2024-28888 |
CWE-416 | High | 11.1.10.1010, 12.1.6.55574, 13.1.4.62748, 2024.3.0.65538 | 01.10.2024 |
SB2024100116 SB2024100138 |
||
| #VU97880 - Use After Free CVE-2024-9243 |
CWE-416 | High | 13.1.4.62748, 2024.3.0.65538 | 01.10.2024 |
SB2024100116 SB2024100138 |
||
| #VU97886 - Use After Free CVE-2024-9254 |
CWE-416 | High | 11.1.10.1010, 12.1.6.55574, 13.1.4.62748, 2024.3.0.65538 | 01.10.2024 |
SB2024100116 SB2024100138 |
||
| #VU89812 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') |
CWE-78 | Medium | 2024.2.2.64388 | 24.05.2024 |
SB2024052464 |
||
| #VU87287 - NULL Pointer Dereference |
CWE-476 | Low | 2024.1.0.63682 | 08.03.2024 |
SB2024030814 SB2024030826 |
||
| #VU87285 - Use After Free CVE-2024-30322 |
CWE-416 | High | 2024.1.0.63682 | 08.03.2024 |
SB2024030814 SB2024030826 |
||
| #VU87284 - Out-of-bounds read CVE-2024-30323 |
CWE-125 | High | 2024.1.0.63682 | 08.03.2024 |
SB2024030814 SB2024030826 |
||
| #VU85616 - Memory corruption CVE-2023-51562 |
CWE-119 | High | 11.1.6.0109, 12.1.2.55366 | 19.01.2024 |
SB2024011921 SB2024012216 |
||
| #VU85615 - Memory corruption CVE-2023-51550 |
CWE-119 | High | 11.1.6.0109, 12.1.2.55366 | 19.01.2024 |
SB2024011921 SB2024012216 |
||
| #VU85614 - Memory corruption CVE-2023-42089 |
CWE-119 | High | 11.1.6.0109, 12.1.2.55366 | 19.01.2024 |
SB2024011921 SB2024012216 |
||
| #VU85613 - Memory corruption CVE-2023-51551 |
CWE-119 | High | 11.1.6.0109, 12.1.2.55366 | 19.01.2024 |
SB2024011921 SB2024012216 |
Showing elements 1 - 20 out of 37