
CVE-2020-11493
https://notcve.org/view.php?id=CVE-2020-11493
04 Sep 2020 — In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to Stream without concern for a crafted XObject. En Foxit Reader y PhantomPDF versiones anteriores a 10.0.1, y PhantomPDF versiones anteriores a 9.7.3, los atacantes pueden obtener información confidencial sobre un objeto no inicializado debido a una transformación directa de un Objecto PDF a un Transmisión sin pr... • https://github.com/fengjixuchui/CVE-2020-11493 • CWE-345: Insufficient Verification of Data Authenticity •

CVE-2020-15637 – Foxit PhantomPDF SetLocalDescription Use-After-Free Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2020-15637
04 Aug 2020 — This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the SetLocalDescription method. By performing actions in JavaScript, an attacker can cause a pointer to be reused after it has been freed. An attacker can leverage this in conjunction with other vulnerabilities t... • https://www.foxitsoftware.com/support/security-bulletins.html • CWE-416: Use After Free •

CVE-2020-15638 – Foxit PhantomPDF JSCreate Type Confusion Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-15638
04 Aug 2020 — This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.2.29539. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the NodeProperties::InferReceiverMapsUnsafe method. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability ... • https://www.foxitsoftware.com/support/security-bulletins.html • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •

CVE-2017-3011
https://notcve.org/view.php?id=CVE-2017-3011
12 Apr 2017 — Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable integer overflow vulnerability in the CCITT fax PDF filter. Successful exploitation could lead to arbitrary code execution. Las versiones de Adobe Acrobat Reader 11.0.19 y anteriores, 15.006.30280 y anteriores, 15.023.20070 y anteriores tienen una vulnerabilidad de desbordamiento entero explotable en el filtro CCITT fax PDF. Una explotación exitosa podría conducir a la ejecución arbitrar... • http://www.securityfocus.com/bid/97548 • CWE-190: Integer Overflow or Wraparound •

CVE-2017-3012
https://notcve.org/view.php?id=CVE-2017-3012
12 Apr 2017 — Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an insecure library loading (DLL hijacking) vulnerability in the OCR plugin. Las versiones de Adobe Acrobat Reader 11.0.19 y anteriores, 15.006.30280 y anteriores, 15.023.20070 y anteriores tienen una vulnerabilidad de carga de la biblioteca insegura (secuestro de DLL) en el complemento de OCR. • http://www.securityfocus.com/bid/97547 • CWE-427: Uncontrolled Search Path Element •

CVE-2017-3013
https://notcve.org/view.php?id=CVE-2017-3013
12 Apr 2017 — Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an insecure library loading (DLL hijacking) vulnerability in a DLL related to remote logging. Las versiones de Adobe Acrobat Reader 11.0.19 y anteriores, 15.006.30280 y anteriores, 15.023.20070 y anteriores tienen una vulnerabilidad de carga de la biblioteca insegura (secuestro DLL) en un DLL relacionado con el registro remoto. • http://www.securityfocus.com/bid/97547 • CWE-427: Uncontrolled Search Path Element •

CVE-2017-3014
https://notcve.org/view.php?id=CVE-2017-3014
12 Apr 2017 — Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable use after free vulnerability in XML Forms Architecture (XFA) related to reset form functionality. Successful exploitation could lead to arbitrary code execution. Las versiones de Adobe Acrobat Reader 11.0.19 y anteriores, 15.006.30280 y anteriores, 15.023.20070 y anteriores tienen un uso después de liberación explotable después de la vulnerabilidad XML Forms Architecture (XFA) relacionad... • http://www.securityfocus.com/bid/97550 • CWE-416: Use After Free •

CVE-2017-3015
https://notcve.org/view.php?id=CVE-2017-3015
12 Apr 2017 — Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the JBIG2 parsing functionality. Successful exploitation could lead to arbitrary code execution. Las versiones de Adobe Acrobat Reader 11.0.19 y anteriores, 15.006.30280 y anteriores, 15.023.20070 y anteriores tienen una vulnerabilidad de corrupción de memoria explotable en la funcionalidad de análisis de JBIG2. Una explotación exitosa podría conducir a... • http://www.securityfocus.com/bid/97556 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-3017
https://notcve.org/view.php?id=CVE-2017-3017
12 Apr 2017 — Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability when handling a malformed PDF file. Successful exploitation could lead to arbitrary code execution. Las versiones de Adobe Acrobat Reader 11.0.19 y anteriores, 15.006.30280 y anteriores, 15.023.20070 y anteriores tienen una vulnerabilidad de corrupción de memoria explotable al manejar un archivo PDF con formato incorrecto. Una explotación exitosa podría co... • http://www.securityfocus.com/bid/97556 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-3018
https://notcve.org/view.php?id=CVE-2017-3018
12 Apr 2017 — Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the renderer functionality. Successful exploitation could lead to arbitrary code execution. Las versiones de Adobe Acrobat Reader 11.0.19 y anteriores, 15.006.30280 y anteriores, 15.023.20070 y anteriores tienen una vulnerabilidad de corrupción de memoria explotable en la funcionalidad de representación. Una explotación exitosa podría conducir a la ejec... • http://www.securityfocus.com/bid/97556 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •