Foxit Reader and PhantomPDF Multiple Security Vulnerabilities

BID:108561

Info

Foxit Reader and PhantomPDF Multiple Security Vulnerabilities

Bugtraq ID: 108561
Class: Boundary Condition Error
CVE: CVE-2019-6755
CVE-2019-6754
CVE-2019-6756
CVE-2019-6757
CVE-2019-6758
CVE-2019-6759
CVE-2019-6760
CVE-2019-6761
CVE-2019-6762
CVE-2019-6763
CVE-2019-6764
CVE-2019-6765
CVE-2019-6766
CVE-2019-6767
CVE-2019-6768
CVE-2019-6769
CVE-2019-6770
CVE-2019-6771
CVE-2019-6772
CVE-2019-6773
Remote: Yes
Local: No
Published: Apr 29 2019 12:00AM
Updated: Apr 29 2019 12:00AM
Credit: Steven Seeley (mr_me) of Source Incite, Hao Li from ADLab of VenusTech, Mat Powell of Trend Micro Zero Day Initiative, juggernaut, kdot, @j00sean (https://twitter.com/j00sean), hungtt28 of Viettel Cyber Security, RockStar, hemidallt, Anonymous
Vulnerable: Foxit Reader 8.3.1
Foxit Reader 8.2.1
Foxit Reader 8.0.2
Foxit Reader 7.3.4
Foxit Reader 7.2.2
Foxit Reader 6.2.1
Foxit Reader 6.1.4
Foxit Reader 6.1.2
Foxit Reader 4.1.1
Foxit Reader 3.1.1 Build 0928
Foxit Reader 2.2.1025
Foxit Reader 9.4.16811
Foxit Reader 9.4.1.16828
Foxit Reader 9.3.0.10826
Foxit Reader 9.2.0.9297
Foxit Reader 9.1.0.5096
Foxit Reader 9.1
Foxit Reader 9.0.1.1049
Foxit Reader 9.0
Foxit Reader 8.3.2.25013
Foxit Reader 8.3.0.14878
Foxit Reader 8.3
Foxit Reader 8.2
Foxit Reader 8.1.4.1208
Foxit Reader 8.1.1
Foxit Reader 8.1.0.1013
Foxit Reader 8.1
Foxit Reader 8.0.5
Foxit Reader 8.0.2.805
Foxit Reader 8.0.0.624
Foxit Reader 8.0
Foxit Reader 7.3.4.311
Foxit Reader 7.3.0.118
Foxit Reader 7.3
Foxit Reader 7.2.8.1124
Foxit Reader 7.2.0.722
Foxit Reader 7.2
Foxit Reader 7.1.5.425
Foxit Reader 7.1.3.320
Foxit Reader 7.1.0.306
Foxit Reader 7.1
Foxit Reader 7.0.6.1126
Foxit Reader 6.2
Foxit Reader 6.1
Foxit Reader 4.1.1.0805
Foxit Reader 4.1
Foxit Reader 2.3
Foxit Reader 2.1
Foxit Reader 2.0.0.0625
Foxit Reader 2.0
Foxit Reader 1.1.1.0602
Foxit Reader 1.1
Foxit PhantomPDF 8.3.1
Foxit PhantomPDF 8.2.1
Foxit PhantomPDF 8.0.2
Foxit PhantomPDF 7.3.4
Foxit PhantomPDF 7.2.2
Foxit PhantomPDF 7.1.5
Foxit PhantomPDF 9.4.1.16828
Foxit PhantomPDF 9.4.0.16811
Foxit PhantomPDF 9.3.0.10826
Foxit PhantomPDF 9.2.0.9297
Foxit PhantomPDF 9.1
Foxit PhantomPDF 9.0.1.1049
Foxit PhantomPDF 9.0
Foxit PhantomPDF 8.4
Foxit PhantomPDF 8.3.8.39677
Foxit PhantomPDF 8.3
Foxit PhantomPDF 8.2
Foxit PhantomPDF 8.1.1.1115
Foxit PhantomPDF 8.1.1
Foxit PhantomPDF 8.1.0.1013
Foxit PhantomPDF 8.1
Foxit PhantomPDF 8.0.5
Foxit PhantomPDF 8.0.2.805
Foxit PhantomPDF 8.0.1.628
Foxit PhantomPDF 8.0
Foxit PhantomPDF 7.3.4.311
Foxit PhantomPDF 7.3.0.118
Foxit PhantomPDF 7.3
Foxit PhantomPDF 7.2.2.929
Foxit PhantomPDF 7.2.0.722
Foxit PhantomPDF 7.2
Foxit PhantomPDF 7.1.5.425
Foxit PhantomPDF 7.1.3.320
Foxit PhantomPDF 7.1.2.311
Foxit PhantomPDF 7.1.0.306
Foxit PhantomPDF 7.1
Foxit PhantomPDF 7.0.6.1126
Foxit Foxit Reader 9.3.10826
Not Vulnerable: Foxit Reader 9.5
Foxit PhantomPDF 9.5

Discussion

Foxit Reader and PhantomPDF Multiple Security Vulnerabilities

Foxit Reader and PhantomPDF are prone to the following vulnerabilities:

1. Multiple arbitrary code-execution vulnerabilities
2. Multiple information disclosure vulnerabilities

Attackers can exploit these issues to execute arbitrary code in the context of the current process or obtain sensitive information. Failed exploit attempts will likely cause denial-of-service conditions.

Exploit / POC

Foxit Reader and PhantomPDF Multiple Security Vulnerabilities

Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].

Solution / Fix

Foxit Reader and PhantomPDF Multiple Security Vulnerabilities

Solution:
Updates are available. Please see the references or vendor advisory for more information.

References

Foxit Reader and PhantomPDF Multiple Security Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report