Kaspersky ID:
KLA91298
Date de la détection:
09/23/2026
Mis à jour:
09/24/2026

Description

Multiple vulnerabilities were found in Foxit Reader. Malicious users can exploit these vulnerabilities to obtain sensitive information, cause denial of service, execute arbitrary code, gain privileges, write local files, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. Exposure of resource to wrong sphere vulnerability in JavaScript can be exploited to obtain sensitive information.
  2. Out-of-bounds read vulnerability in PDF image mask processing can be exploited to obtain sensitive information or cause denial of service.
  3. Use-after-free vulnerability in PDF page-tree handling can be exploited to execute arbitrary code or cause denial of service.
  4. Out-of-bounds write vulnerability in PDF object processing can be exploited to execute arbitrary code or cause denial of service.
  5. Path traversal vulnerability in RichMedia embedded PDF resource handling can be exploited to execute arbitrary code.
  6. Improper cryptographic signature verification vulnerability can be exploited to manipulate signed document content while presenting incorrect signature verification information.
  7. Improper certificate validation vulnerability in the update mechanism can be exploited to execute arbitrary code with elevated privileges.
  8. TOCTOU race condition vulnerability in the update mechanism can be exploited to execute arbitrary code with elevated privileges.
  9. Out-of-bounds read vulnerability in image processing can be exploited to obtain sensitive information or cause denial of service.
  10. Use-after-free vulnerability caused by reentrant zoom and layout operations can be exploited to execute arbitrary code or cause denial of service.
  11. Untrusted pointer dereference vulnerability in FileOpen encryption metadata processing can be exploited to execute arbitrary code or cause denial of service.
  12. Use-after-free vulnerability in image object rendering can be exploited to execute arbitrary code or cause denial of service.
  13. Out-of-bounds write vulnerability when processing malformed PDF data can be exploited to execute arbitrary code or cause denial of service.
  14. Heap-based out-of-bounds write vulnerability in WebP image decoding can be exploited to execute arbitrary code or cause denial of service.
  15. Uncontrolled search path vulnerability in the update mechanism can be exploited to load a malicious library and execute arbitrary code with elevated privileges.
  16. Path traversal vulnerability in PDF attachment handling can be exploited to write malicious files to arbitrary filesystem locations and execute arbitrary code.
  17. Use-after-free vulnerability in PDF object processing can be exploited to execute arbitrary code or cause denial of service.
  18. Out-of-bounds write vulnerability in U3D/GIF texture decoding can be exploited to execute arbitrary code or cause denial of service.
  19. Heap-based out-of-bounds write vulnerability in Circle annotation rendering can be exploited to execute arbitrary code or cause denial of service.
  20. Incorrect permission assignment vulnerability in the Foxit update daemon can be exploited to execute arbitrary code with elevated privileges.
  21. Protection mechanism failure in Safe Reading Mode can be exploited to bypass security restrictions and disclose authentication information through external SMB authentication.
  22. Out-of-bounds read vulnerability caused by improper wide-string range validation can be exploited to obtain sensitive information or cause denial of service.
  23. Heap-based out-of-bounds read vulnerability in JPEG/image object processing can be exploited to obtain sensitive information or cause denial of service.
  24. Use-after-free vulnerability in annotation rich-text processing can be exploited to execute arbitrary code or cause denial of service.
  25. Use-after-free vulnerability in PDF form field handling can be exploited to execute arbitrary code or cause denial of service.
  26. Use-after-free vulnerability caused by reentrant PDF processing can be exploited to execute arbitrary code or cause denial of service.
  27. Use-after-free vulnerability in JavaScript array object handling can be exploited to execute arbitrary code or cause denial of service.
  28. Out-of-bounds write vulnerability in PDF rendering can be exploited to execute arbitrary code or cause denial of service.

Fiches de renseignement originales

Produits associés

Liste CVE

  • CVE-2026-91788
    warning
  • CVE-2026-91789
    critical
  • CVE-2026-91790
    critical
  • CVE-2026-91791
    critical
  • CVE-2026-91792
    critical
  • CVE-2026-91793
    critical
  • CVE-2026-91794
    critical
  • CVE-2026-91795
    critical
  • CVE-2026-91796
    high
  • CVE-2026-91797
    critical
  • CVE-2026-91798
    critical
  • CVE-2026-91799
    critical
  • CVE-2026-91801
    critical
  • CVE-2026-91802
    critical
  • CVE-2026-91803
    critical
  • CVE-2026-91804
    critical
  • CVE-2026-91805
    critical
  • CVE-2026-91806
    critical
  • CVE-2026-91807
    high
  • CVE-2026-91808
    high
  • CVE-2026-91809
    critical
  • CVE-2026-91810
    high
  • CVE-2026-91811
    critical
  • CVE-2026-91812
    critical
  • CVE-2026-91813
    critical
  • CVE-2026-91814
    high
  • CVE-2026-91815
    critical
  • CVE-2026-91816
    critical
  • CVE-2026-91817
    high
  • CVE-2026-91818
    critical

En savoir plus

Découvrez les statistiques de la propagation des vulnérabilités dans votre région statistics.securelist.com

Vous avez trouvé une inexactitude dans la description de cette vulnérabilité ? Faites-le nous savoir !
Kaspersky IT Security Calculator:
Calculez le profil de sécurité de votre entreprise
Apprendre encore plus
Kaspersky!
Votre vie en ligne mérite une protection complète!
Apprendre encore plus
Do you want to save your changes?
Your message has been sent successfully.