CVE-2018-3944
https://notcve.org/view.php?id=CVE-2018-3944
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability. Existe una vulnerabilidad explotable de uso de memoria previamente liberada en el motor JavaScript de Foxit PDF Reader, de Foxit Software, en su versión 9.1.0.5096. • http://www.securitytracker.com/id/1041769 https://talosintelligence.com/vulnerability_reports/TALOS-2018-0611 https://www.foxitsoftware.com/support/security-bulletins.php • CWE-416: Use After Free •
CVE-2018-3943
https://notcve.org/view.php?id=CVE-2018-3943
An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability. Existe una vulnerabilidad explotable de uso de memoria previamente liberada en el motor JavaScript de Foxit PDF Reader, de Foxit Software, en su versión 9.1.0.5096. • http://www.securitytracker.com/id/1041769 https://talosintelligence.com/vulnerability_reports/TALOS-2018-0610 https://www.foxitsoftware.com/support/security-bulletins.php • CWE-416: Use After Free •
CVE-2018-3961
https://notcve.org/view.php?id=CVE-2018-3961
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Creator property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability. Existe una vulnerabilidad de uso de memoria previamente liberada en el motor JavaScript de Foxit PDF Reader, de Foxit Software, en su versión 9.1.0.5096. • https://talosintelligence.com/vulnerability_reports/TALOS-2018-0628 https://www.foxitsoftware.com/support/security-bulletins.php • CWE-416: Use After Free •
CVE-2018-17781
https://notcve.org/view.php?id=CVE-2018-17781
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to trigger Uninitialized Object Information Disclosure because creation of ArrayBuffer and DataView objects is mishandled. Foxit PhantomPDF y Reader en versiones anteriores a la 9.3 permiten que atacantes remotos desencadenen una divulgación de información de objetos sin inicializar debido a que se gestiona de forma incorrecta la creación de objetos ArrayBuffer y DataView. • http://www.securitytracker.com/id/1041769 https://www.foxitsoftware.com/support/security-bulletins.php • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2018-17609
https://notcve.org/view.php?id=CVE-2018-17609
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This relates to one of five distinct types of Annotation objects. Foxit PhantomPDF y Reader en versiones anteriores a la 9.3 permite que atacantes remotos ejecuten código arbitrario o provoquen una denegación de servicio (uso de memoria previamente liberada) debido a que se manejan incorrectamente las propiedades de los objetos Annotation. Esto está relacionado con uno de los cinco tipos diferentes de objetos Annotation. • https://www.foxitsoftware.com/support/security-bulletins.php • CWE-416: Use After Free •