
CVE-2020-10902 – Foxit PhantomPDF U3DBrowser U3D File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-10902
16 Apr 2020 — This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects in PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this vulne... • https://www.foxitsoftware.com/support/security-bulletins.php • CWE-125: Out-of-bounds Read •

CVE-2020-10904 – Foxit PhantomPDF U3DBrowser U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-10904
16 Apr 2020 — This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects in PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnera... • https://www.foxitsoftware.com/support/security-bulletins.php • CWE-787: Out-of-bounds Write •

CVE-2020-10908 – Foxit PhantomPDF Export Type Confusion Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-10908
16 Apr 2020 — This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the Export command of the communication API. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulne... • https://www.foxitsoftware.com/support/security-bulletins.php • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •

CVE-2020-10909 – Foxit PhantomPDF AddWatermark Type Confusion Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-10909
16 Apr 2020 — This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the AddWatermark command of the communication API. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this... • https://www.foxitsoftware.com/support/security-bulletins.php • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •

CVE-2020-10910 – Foxit PhantomPDF RotatePage Type Confusion Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-10910
16 Apr 2020 — This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the RotatePage command of the communication API. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this v... • https://www.foxitsoftware.com/support/security-bulletins.php • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •

CVE-2020-10911 – Foxit PhantomPDF GetFieldValue Type Confusion Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-10911
16 Apr 2020 — This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the GetFieldValue command of the communication API. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage thi... • https://www.foxitsoftware.com/support/security-bulletins.php • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •

CVE-2020-10912 – Foxit PhantomPDF SetFieldValue Type Confusion Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-10912
16 Apr 2020 — This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the SetFieldValue command of the communication API. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage thi... • https://www.foxitsoftware.com/support/security-bulletins.php • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •

CVE-2020-10913 – Foxit PhantomPDF OCRAndExportToExcel Type Confusion Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-10913
16 Apr 2020 — This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the OCRAndExportToExcel command of the communication API. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can levera... • https://www.foxitsoftware.com/support/security-bulletins.php • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •

CVE-2020-8844 – Foxit Reader ConvertToPDF JPEG Parsing Integer Overflow Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-8844
11 Feb 2020 — This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPEG files within CovertToPDF. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulner... • https://www.foxitsoftware.com/support/security-bulletins.php • CWE-190: Integer Overflow or Wraparound •

CVE-2020-8845 – Foxit PhantomPDF AcroForm addWatermarkFromText Use-After-Free Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-8845
11 Feb 2020 — This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of watermarks in AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code i... • https://www.foxitsoftware.com/support/security-bulletins.php • CWE-416: Use After Free •