Description
Multiple vulnerabilities were found in Foxit Reader. Malicious users can exploit these vulnerabilities to obtain sensitive information, execute arbitrary code, cause denial of service, bypass security restrictions.
Below is a complete list of vulnerabilities:
- Out of bounds read vulnerability in AcroForm can be exploited to obtain sensitive information.
- Use after free vulnerability in JavaScript engine can be exploited to cause denial of service or execute arbitrary code.
- Use after free vulnerability in Annotation can be exploited to execute arbitrary code.
- Type confusion vulnerability in Javascript checkThisBox method can be exploited to cause denial of service and execute arbitrary code.
- Use after free vulnerability in AcroForm Doc Object can be exploited to execute arbitrary code.
- Out of bounds read vulnerability in AcroForm signature can be exploited to execute arbitrary code.
- Out of bounds read vulnerability in PDF File Parsing can be exploited to obtain sensitive information.
- Out of bounds write vulnerability in AcroForm Doc Object can be exploited to execute arbitrary code.
- Use after free vulnerability in Annotation can be exploited to obtain sensitive information.
- Use after free vulnerability in XFA Annotation can be exploited to execute arbitrary code.
- Out of bounds read vulnerability in Doc Object can be exploited to obtain sensitive information.
- Out of bounds read vulnerability in AcroForm Doc Object can be exploited to obtain sensitive information.
Fiches de renseignement originales
Exploitation
Public exploits exist for this vulnerability.
Produits associés
Liste CVE
- CVE-2023-38115 warning
- CVE-2023-28744 critical
- CVE-2023-38111 critical
- CVE-2023-32664 critical
- CVE-2023-33866 critical
- CVE-2023-38117 critical
- CVE-2023-33876 critical
- CVE-2023-38119 critical
- CVE-2023-38106 warning
- CVE-2023-38118 critical
- CVE-2023-38113 warning
- CVE-2023-38114 critical
- CVE-2023-27379 critical
- CVE-2023-38112 critical
- CVE-2023-38116 warning
- CVE-2023-38105 warning
- CVE-2023-38110 warning
- CVE-2023-38108 warning
- CVE-2023-38109 warning
- CVE-2023-38107 critical
En savoir plus
Découvrez les statistiques de la propagation des vulnérabilités dans votre région statistics.securelist.com
Vous avez trouvé une inexactitude dans la description de cette vulnérabilité ? Faites-le nous savoir !