Popis
Multiple vulnerabilities were found in Foxit Reader. Malicious users can exploit these vulnerabilities to obtain sensitive information, cause denial of service, execute arbitrary code, gain privileges, write local files, bypass security restrictions.
Below is a complete list of vulnerabilities:
- Exposure of resource to wrong sphere vulnerability in JavaScript can be exploited to obtain sensitive information.
- Out-of-bounds read vulnerability in PDF image mask processing can be exploited to obtain sensitive information or cause denial of service.
- Use-after-free vulnerability in PDF page-tree handling can be exploited to execute arbitrary code or cause denial of service.
- Out-of-bounds write vulnerability in PDF object processing can be exploited to execute arbitrary code or cause denial of service.
- Path traversal vulnerability in RichMedia embedded PDF resource handling can be exploited to execute arbitrary code.
- Improper cryptographic signature verification vulnerability can be exploited to manipulate signed document content while presenting incorrect signature verification information.
- Improper certificate validation vulnerability in the update mechanism can be exploited to execute arbitrary code with elevated privileges.
- TOCTOU race condition vulnerability in the update mechanism can be exploited to execute arbitrary code with elevated privileges.
- Out-of-bounds read vulnerability in image processing can be exploited to obtain sensitive information or cause denial of service.
- Use-after-free vulnerability caused by reentrant zoom and layout operations can be exploited to execute arbitrary code or cause denial of service.
- Untrusted pointer dereference vulnerability in FileOpen encryption metadata processing can be exploited to execute arbitrary code or cause denial of service.
- Use-after-free vulnerability in image object rendering can be exploited to execute arbitrary code or cause denial of service.
- Out-of-bounds write vulnerability when processing malformed PDF data can be exploited to execute arbitrary code or cause denial of service.
- Heap-based out-of-bounds write vulnerability in WebP image decoding can be exploited to execute arbitrary code or cause denial of service.
- Uncontrolled search path vulnerability in the update mechanism can be exploited to load a malicious library and execute arbitrary code with elevated privileges.
- Path traversal vulnerability in PDF attachment handling can be exploited to write malicious files to arbitrary filesystem locations and execute arbitrary code.
- Use-after-free vulnerability in PDF object processing can be exploited to execute arbitrary code or cause denial of service.
- Out-of-bounds write vulnerability in U3D/GIF texture decoding can be exploited to execute arbitrary code or cause denial of service.
- Heap-based out-of-bounds write vulnerability in Circle annotation rendering can be exploited to execute arbitrary code or cause denial of service.
- Incorrect permission assignment vulnerability in the Foxit update daemon can be exploited to execute arbitrary code with elevated privileges.
- Protection mechanism failure in Safe Reading Mode can be exploited to bypass security restrictions and disclose authentication information through external SMB authentication.
- Out-of-bounds read vulnerability caused by improper wide-string range validation can be exploited to obtain sensitive information or cause denial of service.
- Heap-based out-of-bounds read vulnerability in JPEG/image object processing can be exploited to obtain sensitive information or cause denial of service.
- Use-after-free vulnerability in annotation rich-text processing can be exploited to execute arbitrary code or cause denial of service.
- Use-after-free vulnerability in PDF form field handling can be exploited to execute arbitrary code or cause denial of service.
- Use-after-free vulnerability caused by reentrant PDF processing can be exploited to execute arbitrary code or cause denial of service.
- Use-after-free vulnerability in JavaScript array object handling can be exploited to execute arbitrary code or cause denial of service.
- Out-of-bounds write vulnerability in PDF rendering can be exploited to execute arbitrary code or cause denial of service.
Oficiální doporučení
Související produkty
seznam CVE
- CVE-2026-91788 warning
- CVE-2026-91789 critical
- CVE-2026-91790 critical
- CVE-2026-91791 critical
- CVE-2026-91792 critical
- CVE-2026-91793 critical
- CVE-2026-91794 critical
- CVE-2026-91795 critical
- CVE-2026-91796 high
- CVE-2026-91797 critical
- CVE-2026-91798 critical
- CVE-2026-91799 critical
- CVE-2026-91801 critical
- CVE-2026-91802 critical
- CVE-2026-91803 critical
- CVE-2026-91804 critical
- CVE-2026-91805 critical
- CVE-2026-91806 critical
- CVE-2026-91807 high
- CVE-2026-91808 high
- CVE-2026-91809 critical
- CVE-2026-91810 high
- CVE-2026-91811 critical
- CVE-2026-91812 critical
- CVE-2026-91813 critical
- CVE-2026-91814 high
- CVE-2026-91815 critical
- CVE-2026-91816 critical
- CVE-2026-91817 high
- CVE-2026-91818 critical
Zobrazit více
Zjistěte statistiky zranitelností šířících se ve vaší oblasti statistics.securelist.com
Našli jste v popisu této chyby zabezpečení nepřesnost? Dej nám vědět!