CVE-2021-41784
https://notcve.org/view.php?id=CVE-2021-41784
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled. Foxit PDF Reader versiones anteriores a 11.1 y PDF Editor versiones anteriores a 11.1, y PhantomPDF versiones anteriores a 10.1.6, permiten a atacantes desencadenar un uso de memoria previamente liberada y ejecutar código arbitrario porque JavaScript está manejado inapropiadamente • https://github.com/Jeromeyoung/CVE-2021-41784 https://www.foxit.com/support/security-bulletins.html • CWE-416: Use After Free •
CVE-2021-41785
https://notcve.org/view.php?id=CVE-2021-41785
Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled. Foxit PDF Reader versiones anteriores a 11.1 y PDF Editor versiones anteriores a 11.1, y PhantomPDF versiones anteriores a 10.1.6, permiten a atacantes desencadenar un uso de memoria previamente liberada y ejecutar código arbitrario debido a un manejo inapropiado de JavaScript • https://www.foxit.com/support/security-bulletins.html • CWE-416: Use After Free •
CVE-2022-25641
https://notcve.org/view.php?id=CVE-2022-25641
Foxit PDF Reader before 11.2.2 and PDF Editor before 11.2.2, and PhantomPDF before 10.1.8, mishandle cross-reference information during compressed-object parsing within signed documents. This leads to delivery of incorrect signature information via an Incremental Saving Attack and a Shadow Attack. Foxit PDF Reader versiones anteriores a 11.2.2 y PDF Editor versiones anteriores a 11.2.2, y PhantomPDF versiones anteriores a 10.1.8, manejan inapropiadamente la información de referencias cruzadas durante el análisis de objetos comprimidos dentro de los documentos firmados. Esto conlleva a una entrega de información de firma incorrecta por medio de un Ataque de Guardado Incremental y un Ataque de Sombra • https://www.foxit.com/support/security-bulletins.html •
CVE-2022-26979
https://notcve.org/view.php?id=CVE-2022-26979
Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL. Foxit PDF Reader versiones anteriores a 12.0.1 y PDF Editor versiones anteriores a 12.0.1, permiten una desreferencia de puntero NULL cuando this.Span es usada para oState de Collab.addStateModel, porque this.Span.text puede ser NULL • https://drive.google.com/file/d/1WpwDgVRU-Mb792z6dgDoWMXDRSeB8ZLU/view?usp=sharing https://www.foxit.com/support/security-bulletins.html • CWE-476: NULL Pointer Dereference •
CVE-2022-27944
https://notcve.org/view.php?id=CVE-2022-27944
Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow an exportXFAData NULL pointer dereference. Foxit PDF Reader versiones anteriores a 12.0.1 y PDF Editor versiones anteriores a 12.0.1, permiten una desreferencia de puntero NULL en exportXFAData • https://drive.google.com/file/d/1hNjladTTP3tq7TL2Au5pdMI4nfJkUEvU/view?usp=sharing https://www.foxit.com/support/security-bulletins.html • CWE-476: NULL Pointer Dereference •