📦

phantompdf

Vendor: foxitsoftware

Actively Exploited 0 CISA KEV List
PoC / Exploits 9 Code Available
Total RCEs 301 Remote Access
Total CVEs 804 Total Indexed
Avg. EPSS 3.70% Exploit Prob.
Latest CVE CVE-2022-25641 Aug 29

Security Vulnerability Index

Page 1 / 81
5.5 CVSS

Foxit PDF Reader before 11.2.2 and PDF Editor before 11.2.2, and PhantomPDF before 10.1.8, mishandle cross-reference information during compressed-object parsing within signed documents. This leads to delivery of incorrect signature information via an Incremental Saving Attack and a Shadow Attack.

EPSS: 0.19%
7.8 CVSS

Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.

EPSS: 1.25%
7.8 CVSS
CVE-2021-41784
RCE Exploit Found

Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.

EPSS: 0.68%
7.8 CVSS

Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.

EPSS: 1.25%
7.8 CVSS

Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.

EPSS: 1.25%
7.8 CVSS

Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.

EPSS: 1.25%
7.8 CVSS

Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.

EPSS: 0.50%
5.5 CVSS

Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An attacker can write to an arbitrary file, and display controlled contents, during signature verification.

EPSS: 0.18%
9.8 CVSS

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.

EPSS: 0.99%
9.8 CVSS

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not validated.

EPSS: 1.12%