CVE tracker
393 subscribers
5.68K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-91799 - Foxit Editor/Reader Array resetForm Use-After-Free Vulnerability

CVE ID :CVE-2026-91799
Published : Sept. 23, 2026, 8:17 a.m. | 57 minutes ago
Description :A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of JavaScript array objects. A specially crafted PDF may cause the application to access a released object during array processing, potentially resulting in application crashes or arbitrary code execution.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91800 - Foxit PDF Editor installer local privilege escalation

CVE ID :CVE-2026-91800
Published : Sept. 23, 2026, 8:17 a.m. | 57 minutes ago
Description :A local privilege escalation vulnerability exists in the installer of Foxit PDF Editor for macOS due to insufficient validation of a user-modifiable configuration value during high-privilege upgrades. A local attacker could exploit this issue to execute arbitrary commands with root privileges.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91801 - Foxit PDF Editor/Reader RichMedia Annotation Directory Traversal Remote Code Execution Vulnerability

CVE ID :CVE-2026-91801
Published : Sept. 23, 2026, 8:17 a.m. | 57 minutes ago
Description :A path traversal vulnerability exists in Foxit PDF Editor/Reader's handling of embedded PDF resources. Insufficient validation of resource file paths may allow files to be written outside their intended locations, potentially enabling arbitrary code execution.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91802 - Foxit PDF Editor/Reader — Heap Buffer Overflow in WebP Image Decoding via Bitmap Stride Confusion

CVE ID :CVE-2026-91802
Published : Sept. 23, 2026, 8:17 a.m. | 57 minutes ago
Description :A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s WebP image decoding due to improper handling of bitmap stride and target buffer formats. Successful exploitation could result in an application crash.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91803 - Security Vulnerability Report – Foxit PDF Editor/Reader Updater DLL Search Path Hijacking

CVE ID :CVE-2026-91803
Published : Sept. 23, 2026, 8:17 a.m. | 57 minutes ago
Description :A local privilege escalation vulnerability exists in the updater of Foxit PDF Editor/Reader due to unsafe loading of dynamic-link libraries from a user-writable directory during high-privilege operations. A local attacker could exploit this issue to execute code with elevated privileges.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91804 - Foxit PDF Editor/Reader Out-of-bounds Write Vulnerability While Rendering

CVE ID :CVE-2026-91804
Published : Sept. 23, 2026, 8:17 a.m. | 57 minutes ago
Description :A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s rendering of Circle annotations with malformed Cloudy appearance streams in specially crafted PDF files. Insufficient validation of the appearance geometry can result in memory corruption and application crashes.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91805 - Use-after-free Vulnerability in Foxit PDF Editor/Reader Page-tree Handling

CVE ID :CVE-2026-91805
Published : Sept. 23, 2026, 8:17 a.m. | 57 minutes ago
Description :A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s PDF page-tree handling. A specially crafted PDF can trigger page-structure changes during rendering, causing the application to access released page objects and resulting in memory corruption and an application crash.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91806 - Foxit PDF Editor/Reader Doc Object Use-After-Free Information Disclosure Vulnerability

CVE ID :CVE-2026-91806
Published : Sept. 23, 2026, 8:17 a.m. | 57 minutes ago
Description :A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF form fields. Embedded JavaScript may access form-field references after the corresponding fields have been released, resulting in an application crash.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91807 - Foxit PDF Editor/Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

CVE ID :CVE-2026-91807
Published : Sept. 23, 2026, 8:17 a.m. | 57 minutes ago
Description :A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed image soft-mask data. Insufficient validation of the soft-mask data attribute during image parsing may cause an arithmetic underflow, resulting in an out-of-bounds read and application crash.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91808 - Foxit PDF Editor/Reader JPEG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

CVE ID :CVE-2026-91808
Published : Sept. 23, 2026, 8:17 a.m. | 57 minutes ago
Description :A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor Reader’s handling of PDF image objects with inconsistent compression metadata. Insufficient validation during image decoding may result in an undersized buffer and an out-of-bounds read during rendering, causing an application crash.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91809 - Foxit PDF Editor/Reader Annotation Use-After-Free Information Disclosure Vulnerability

CVE ID :CVE-2026-91809
Published : Sept. 23, 2026, 8:17 a.m. | 57 minutes ago
Description :A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF form fields. Improper validation during field-name traversal may cause the application to access a released object, resulting in an application crash.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91810 - Foxit PDF Editor/Reader Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability

CVE ID :CVE-2026-91810
Published : Sept. 23, 2026, 8:17 a.m. | 57 minutes ago
Description :A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF image masks. Inconsistent image metadata may cause incorrect alpha-channel processing during rendering, resulting in an out-of-bounds read and application crash.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91811 - Foxit PDF Editor/Reader PRC Stream Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

CVE ID :CVE-2026-91811
Published : Sept. 23, 2026, 8:17 a.m. | 57 minutes ago
Description :A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s PRC parser due to insufficient validation of vertex indices in triangular fan texture meshes. Successful exploitation could result in memory corruption and an application crash.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91812 - Foxit PDF Editor/Reader FoxitUpdater Improper Certificate Validation Local Privilege Escalation Vulnerability

CVE ID :CVE-2026-91812
Published : Sept. 23, 2026, 8:17 a.m. | 57 minutes ago
Description :A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows man-in-the-middle attackers to bypass certificate validation and package integrity checks, potentially enabling arbitrary code execution with system privileges.
Severity: 7.9 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91813 - Foxit PDF Editor/Reader FoxitUpdater Race Condition Local Privilege Escalation Vulnerability

CVE ID :CVE-2026-91813
Published : Sept. 23, 2026, 8:17 a.m. | 57 minutes ago
Description :A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replaced between download and high-privilege extraction due to insufficient file locking and integrity validation. This could enable local attackers to execute arbitrary code with elevated privileges.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91814 - Security vulnerability: Foxit PDF Editor/Reader Fails to Detect Modifications to Signed Documents Displaying Newly Added Content

CVE ID :CVE-2026-91814
Published : Sept. 23, 2026, 8:17 a.m. | 57 minutes ago
Description :A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of incrementally updated PDF documents. Changes to visible document content may not invalidate the existing signature, allowing attackers to alter signed content and potentially carry out content spoofing while the document continues to appear validly signed.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91815 - Foxit PDF Editor/Reader JPEG2000 Parsing Memory Corruption Remote Code Execution Vulnerability

CVE ID :CVE-2026-91815
Published : Sept. 23, 2026, 8:17 a.m. | 57 minutes ago
Description :Foxit PDF Editor/Reader does not perform sufficient verification of the JPEG2000 image metadata in the PDF file, which leads to out-of-bounds write in the heap buffer during decoding, potentially causing the program to crash and introducing the risk of arbitrary code execution.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91816 - Foxit PDF Editor/Reader AcroForm Use-After-Free Remote Code Execution Vulnerability

CVE ID :CVE-2026-91816
Published : Sept. 23, 2026, 8:17 a.m. | 57 minutes ago
Description :A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations. Reentrant annotation deletion triggered by embedded JavaScript can cause the application to access an annotation object after it has been released, resulting in a use-after-free condition and application crash.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91817 - Foxit PDF Editor/Reader AcroForm Out-of-Bounds Read Remote Code Execution Vulnerability

CVE ID :CVE-2026-91817
Published : Sept. 23, 2026, 8:17 a.m. | 57 minutes ago
Description :A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded PDF JavaScript. Insufficient validation of string-deletion ranges can cause an integer underflow, resulting in an out-of-bounds read and application crash.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91818 - Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability

CVE ID :CVE-2026-91818
Published : Sept. 23, 2026, 8:17 a.m. | 57 minutes ago
Description :A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, which is subsequently accessed, resulting in an application crash.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92378 - uniFLOW Online Legacy UI Previous login session retained when entering Reduced Function Login

CVE ID :CVE-2026-92378
Published : Sept. 23, 2026, 8:17 a.m. | 57 minutes ago
Description :A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online. Under specific timing conditions during Service Offline Emergency Mode, a previously authenticated session may be retained after logout, which could allow a subsequent user to be authenticated as the previous user and gain unauthorised limited access to device functionality.
Severity: 4.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...