Kaspersky ID:
KLA91298
検出日:
09/23/2026
更新日:
09/24/2026

説明

Multiple vulnerabilities were found in Foxit Reader. Malicious users can exploit these vulnerabilities to obtain sensitive information, cause denial of service, execute arbitrary code, gain privileges, write local files, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. Exposure of resource to wrong sphere vulnerability in JavaScript can be exploited to obtain sensitive information.
  2. Out-of-bounds read vulnerability in PDF image mask processing can be exploited to obtain sensitive information or cause denial of service.
  3. Use-after-free vulnerability in PDF page-tree handling can be exploited to execute arbitrary code or cause denial of service.
  4. Out-of-bounds write vulnerability in PDF object processing can be exploited to execute arbitrary code or cause denial of service.
  5. Path traversal vulnerability in RichMedia embedded PDF resource handling can be exploited to execute arbitrary code.
  6. Improper cryptographic signature verification vulnerability can be exploited to manipulate signed document content while presenting incorrect signature verification information.
  7. Improper certificate validation vulnerability in the update mechanism can be exploited to execute arbitrary code with elevated privileges.
  8. TOCTOU race condition vulnerability in the update mechanism can be exploited to execute arbitrary code with elevated privileges.
  9. Out-of-bounds read vulnerability in image processing can be exploited to obtain sensitive information or cause denial of service.
  10. Use-after-free vulnerability caused by reentrant zoom and layout operations can be exploited to execute arbitrary code or cause denial of service.
  11. Untrusted pointer dereference vulnerability in FileOpen encryption metadata processing can be exploited to execute arbitrary code or cause denial of service.
  12. Use-after-free vulnerability in image object rendering can be exploited to execute arbitrary code or cause denial of service.
  13. Out-of-bounds write vulnerability when processing malformed PDF data can be exploited to execute arbitrary code or cause denial of service.
  14. Heap-based out-of-bounds write vulnerability in WebP image decoding can be exploited to execute arbitrary code or cause denial of service.
  15. Uncontrolled search path vulnerability in the update mechanism can be exploited to load a malicious library and execute arbitrary code with elevated privileges.
  16. Path traversal vulnerability in PDF attachment handling can be exploited to write malicious files to arbitrary filesystem locations and execute arbitrary code.
  17. Use-after-free vulnerability in PDF object processing can be exploited to execute arbitrary code or cause denial of service.
  18. Out-of-bounds write vulnerability in U3D/GIF texture decoding can be exploited to execute arbitrary code or cause denial of service.
  19. Heap-based out-of-bounds write vulnerability in Circle annotation rendering can be exploited to execute arbitrary code or cause denial of service.
  20. Incorrect permission assignment vulnerability in the Foxit update daemon can be exploited to execute arbitrary code with elevated privileges.
  21. Protection mechanism failure in Safe Reading Mode can be exploited to bypass security restrictions and disclose authentication information through external SMB authentication.
  22. Out-of-bounds read vulnerability caused by improper wide-string range validation can be exploited to obtain sensitive information or cause denial of service.
  23. Heap-based out-of-bounds read vulnerability in JPEG/image object processing can be exploited to obtain sensitive information or cause denial of service.
  24. Use-after-free vulnerability in annotation rich-text processing can be exploited to execute arbitrary code or cause denial of service.
  25. Use-after-free vulnerability in PDF form field handling can be exploited to execute arbitrary code or cause denial of service.
  26. Use-after-free vulnerability caused by reentrant PDF processing can be exploited to execute arbitrary code or cause denial of service.
  27. Use-after-free vulnerability in JavaScript array object handling can be exploited to execute arbitrary code or cause denial of service.
  28. Out-of-bounds write vulnerability in PDF rendering can be exploited to execute arbitrary code or cause denial of service.

オリジナルアドバイザリー

関連製品

CVEリスト

  • CVE-2026-91788
    warning
  • CVE-2026-91789
    critical
  • CVE-2026-91790
    critical
  • CVE-2026-91791
    critical
  • CVE-2026-91792
    critical
  • CVE-2026-91793
    critical
  • CVE-2026-91794
    critical
  • CVE-2026-91795
    critical
  • CVE-2026-91796
    high
  • CVE-2026-91797
    critical
  • CVE-2026-91798
    critical
  • CVE-2026-91799
    critical
  • CVE-2026-91801
    critical
  • CVE-2026-91802
    critical
  • CVE-2026-91803
    critical
  • CVE-2026-91804
    critical
  • CVE-2026-91805
    critical
  • CVE-2026-91806
    critical
  • CVE-2026-91807
    high
  • CVE-2026-91808
    high
  • CVE-2026-91809
    critical
  • CVE-2026-91810
    high
  • CVE-2026-91811
    critical
  • CVE-2026-91812
    critical
  • CVE-2026-91813
    critical
  • CVE-2026-91814
    high
  • CVE-2026-91815
    critical
  • CVE-2026-91816
    critical
  • CVE-2026-91817
    high
  • CVE-2026-91818
    critical

も参照してください

お住まいの地域に広がる脆弱性の統計をご覧ください statistics.securelist.com

この脆弱性についての記述に不正確な点がありますか? お知らせください!
Kaspersky IT Security Calculator
も参照してください
新しいカスペルスキー
あなたのデジタルライフを守る
も参照してください
Do you want to save your changes?
Your message has been sent successfully.