๐จ CVE-2026-91800
A local privilege escalation vulnerability exists in the installer of Foxit PDF Editor for macOS due to insufficient validation of a user-modifiable configuration value during high-privilege upgrades. A local attacker could exploit this issue to execute arbitrary commands with root privileges.
๐@cveNotify
A local privilege escalation vulnerability exists in the installer of Foxit PDF Editor for macOS due to insufficient validation of a user-modifiable configuration value during high-privilege upgrades. A local attacker could exploit this issue to execute arbitrary commands with root privileges.
๐@cveNotify
Foxit
Security Bulletins & Vulnerability Updates | Foxit
Access Foxit security bulletins and vulnerability updates, including CVEs, affected products, and recommended security fixes for enterprise users.
๐จ CVE-2026-91801
A path traversal vulnerability exists in Foxit PDF Editor/Reader's handling of embedded PDF resources. Insufficient validation of resource file paths may allow files to be written outside their intended locations, potentially enabling arbitrary code execution.
๐@cveNotify
A path traversal vulnerability exists in Foxit PDF Editor/Reader's handling of embedded PDF resources. Insufficient validation of resource file paths may allow files to be written outside their intended locations, potentially enabling arbitrary code execution.
๐@cveNotify
Foxit
Security Bulletins & Vulnerability Updates | Foxit
Access Foxit security bulletins and vulnerability updates, including CVEs, affected products, and recommended security fixes for enterprise users.
๐จ CVE-2026-91802
A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Readerโs WebP image decoding due to improper handling of bitmap stride and target buffer formats. Successful exploitation could result in an application crash.
๐@cveNotify
A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Readerโs WebP image decoding due to improper handling of bitmap stride and target buffer formats. Successful exploitation could result in an application crash.
๐@cveNotify
Foxit
Security Bulletins & Vulnerability Updates | Foxit
Access Foxit security bulletins and vulnerability updates, including CVEs, affected products, and recommended security fixes for enterprise users.
๐จ CVE-2026-91803
A local privilege escalation vulnerability exists in the updater of Foxit PDF Editor/Reader due to unsafe loading of dynamic-link libraries from a user-writable directory during high-privilege operations. A local attacker could exploit this issue to execute code with elevated privileges.
๐@cveNotify
A local privilege escalation vulnerability exists in the updater of Foxit PDF Editor/Reader due to unsafe loading of dynamic-link libraries from a user-writable directory during high-privilege operations. A local attacker could exploit this issue to execute code with elevated privileges.
๐@cveNotify
Foxit
Security Bulletins & Vulnerability Updates | Foxit
Access Foxit security bulletins and vulnerability updates, including CVEs, affected products, and recommended security fixes for enterprise users.
๐จ CVE-2026-91804
A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Readerโs rendering of Circle annotations with malformed Cloudy appearance streams in specially crafted PDF files. Insufficient validation of the appearance geometry can result in memory corruption and application crashes.
๐@cveNotify
A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Readerโs rendering of Circle annotations with malformed Cloudy appearance streams in specially crafted PDF files. Insufficient validation of the appearance geometry can result in memory corruption and application crashes.
๐@cveNotify
Foxit
Security Bulletins & Vulnerability Updates | Foxit
Access Foxit security bulletins and vulnerability updates, including CVEs, affected products, and recommended security fixes for enterprise users.
๐จ CVE-2026-91805
A use-after-free vulnerability exists in Foxit PDF Editor/Readerโs PDF page-tree handling. A specially crafted PDF can trigger page-structure changes during rendering, causing the application to access released page objects and resulting in memory corruption and an application crash.
๐@cveNotify
A use-after-free vulnerability exists in Foxit PDF Editor/Readerโs PDF page-tree handling. A specially crafted PDF can trigger page-structure changes during rendering, causing the application to access released page objects and resulting in memory corruption and an application crash.
๐@cveNotify
Foxit
Security Bulletins & Vulnerability Updates | Foxit
Access Foxit security bulletins and vulnerability updates, including CVEs, affected products, and recommended security fixes for enterprise users.
๐จ CVE-2026-91807
A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Readerโs handling of malformed image soft-mask data. Insufficient validation of the soft-mask data attribute during image parsing may cause an arithmetic underflow, resulting in an out-of-bounds read and application crash.
๐@cveNotify
A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Readerโs handling of malformed image soft-mask data. Insufficient validation of the soft-mask data attribute during image parsing may cause an arithmetic underflow, resulting in an out-of-bounds read and application crash.
๐@cveNotify
Foxit
Security Bulletins & Vulnerability Updates | Foxit
Access Foxit security bulletins and vulnerability updates, including CVEs, affected products, and recommended security fixes for enterprise users.
๐จ CVE-2026-91808
A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor Readerโs handling of PDF image objects with inconsistent compression metadata. Insufficient validation during image decoding may result in an undersized buffer and an out-of-bounds read during rendering, causing an application crash.
๐@cveNotify
A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor Readerโs handling of PDF image objects with inconsistent compression metadata. Insufficient validation during image decoding may result in an undersized buffer and an out-of-bounds read during rendering, causing an application crash.
๐@cveNotify
Foxit
Security Bulletins & Vulnerability Updates | Foxit
Access Foxit security bulletins and vulnerability updates, including CVEs, affected products, and recommended security fixes for enterprise users.
๐จ CVE-2026-91809
A use-after-free vulnerability exists in Foxit PDF Editor/Readerโs handling of malformed PDF form fields. Improper validation during field-name traversal may cause the application to access a released object, resulting in an application crash.
๐@cveNotify
A use-after-free vulnerability exists in Foxit PDF Editor/Readerโs handling of malformed PDF form fields. Improper validation during field-name traversal may cause the application to access a released object, resulting in an application crash.
๐@cveNotify
Foxit
Security Bulletins & Vulnerability Updates | Foxit
Access Foxit security bulletins and vulnerability updates, including CVEs, affected products, and recommended security fixes for enterprise users.
๐จ CVE-2026-91810
A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Readerโs handling of malformed PDF image masks. Inconsistent image metadata may cause incorrect alpha-channel processing during rendering, resulting in an out-of-bounds read and application crash.
๐@cveNotify
A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Readerโs handling of malformed PDF image masks. Inconsistent image metadata may cause incorrect alpha-channel processing during rendering, resulting in an out-of-bounds read and application crash.
๐@cveNotify
Foxit
Security Bulletins & Vulnerability Updates | Foxit
Access Foxit security bulletins and vulnerability updates, including CVEs, affected products, and recommended security fixes for enterprise users.
๐จ CVE-2026-91811
A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Readerโs PRC parser due to insufficient validation of vertex indices in triangular fan texture meshes. Successful exploitation could result in memory corruption and an application crash.
๐@cveNotify
A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Readerโs PRC parser due to insufficient validation of vertex indices in triangular fan texture meshes. Successful exploitation could result in memory corruption and an application crash.
๐@cveNotify
Foxit
Security Bulletins & Vulnerability Updates | Foxit
Access Foxit security bulletins and vulnerability updates, including CVEs, affected products, and recommended security fixes for enterprise users.
๐จ CVE-2026-91812
A vulnerability in Foxit PDF Editor/Readerโs update mechanism allows man-in-the-middle attackers to bypass certificate validation and package integrity checks, potentially enabling arbitrary code execution with system privileges.
๐@cveNotify
A vulnerability in Foxit PDF Editor/Readerโs update mechanism allows man-in-the-middle attackers to bypass certificate validation and package integrity checks, potentially enabling arbitrary code execution with system privileges.
๐@cveNotify
Foxit
Security Bulletins & Vulnerability Updates | Foxit
Access Foxit security bulletins and vulnerability updates, including CVEs, affected products, and recommended security fixes for enterprise users.
๐จ CVE-2026-91813
A vulnerability in Foxit PDF Editor/Readerโs update mechanism allows an update package to be replaced between download and high-privilege extraction due to insufficient file locking and integrity validation. This could enable local attackers to execute arbitrary code with elevated privileges.
๐@cveNotify
A vulnerability in Foxit PDF Editor/Readerโs update mechanism allows an update package to be replaced between download and high-privilege extraction due to insufficient file locking and integrity validation. This could enable local attackers to execute arbitrary code with elevated privileges.
๐@cveNotify
Foxit
Security Bulletins & Vulnerability Updates | Foxit
Access Foxit security bulletins and vulnerability updates, including CVEs, affected products, and recommended security fixes for enterprise users.
๐จ CVE-2026-91814
A signature validation vulnerability exists in Foxit PDF Editor/Readerโs handling of incrementally updated PDF documents. Changes to visible document content may not invalidate the existing signature, allowing attackers to alter signed content and potentially carry out content spoofing while the document continues to appear validly signed.
๐@cveNotify
A signature validation vulnerability exists in Foxit PDF Editor/Readerโs handling of incrementally updated PDF documents. Changes to visible document content may not invalidate the existing signature, allowing attackers to alter signed content and potentially carry out content spoofing while the document continues to appear validly signed.
๐@cveNotify
Foxit
Security Bulletins & Vulnerability Updates | Foxit
Access Foxit security bulletins and vulnerability updates, including CVEs, affected products, and recommended security fixes for enterprise users.
๐จ CVE-2026-91815
Foxit PDF Editor/Reader does not perform sufficient verification of the JPEG2000 image metadata in the PDF file, which leads to out-of-bounds write in the heap buffer during decoding, potentially causing the program to crash and introducing the risk of arbitrary code execution.
๐@cveNotify
Foxit PDF Editor/Reader does not perform sufficient verification of the JPEG2000 image metadata in the PDF file, which leads to out-of-bounds write in the heap buffer during decoding, potentially causing the program to crash and introducing the risk of arbitrary code execution.
๐@cveNotify
Foxit
Security Bulletins & Vulnerability Updates | Foxit
Access Foxit security bulletins and vulnerability updates, including CVEs, affected products, and recommended security fixes for enterprise users.
๐จ CVE-2026-91816
A use-after-free vulnerability exists in Foxit PDF Editor/Readerโs handling of PDF annotations. Reentrant annotation deletion triggered by embedded JavaScript can cause the application to access an annotation object after it has been released, resulting in a use-after-free condition and application crash.
๐@cveNotify
A use-after-free vulnerability exists in Foxit PDF Editor/Readerโs handling of PDF annotations. Reentrant annotation deletion triggered by embedded JavaScript can cause the application to access an annotation object after it has been released, resulting in a use-after-free condition and application crash.
๐@cveNotify
Foxit
Security Bulletins & Vulnerability Updates | Foxit
Access Foxit security bulletins and vulnerability updates, including CVEs, affected products, and recommended security fixes for enterprise users.
๐จ CVE-2026-91817
A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Readerโs handling of wide strings in embedded PDF JavaScript. Insufficient validation of string-deletion ranges can cause an integer underflow, resulting in an out-of-bounds read and application crash.
๐@cveNotify
A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Readerโs handling of wide strings in embedded PDF JavaScript. Insufficient validation of string-deletion ranges can cause an integer underflow, resulting in an out-of-bounds read and application crash.
๐@cveNotify
Foxit
Security Bulletins & Vulnerability Updates | Foxit
Access Foxit security bulletins and vulnerability updates, including CVEs, affected products, and recommended security fixes for enterprise users.
๐จ CVE-2026-91818
A use-after-free vulnerability exists in Foxit PDF Editor/Readerโs JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, which is subsequently accessed, resulting in an application crash.
๐@cveNotify
A use-after-free vulnerability exists in Foxit PDF Editor/Readerโs JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, which is subsequently accessed, resulting in an application crash.
๐@cveNotify
Foxit
Security Bulletins & Vulnerability Updates | Foxit
Access Foxit security bulletins and vulnerability updates, including CVEs, affected products, and recommended security fixes for enterprise users.
๐จ CVE-2026-92378
A session management
vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware
uniFLOW Online. Under specific timing conditions during Service Offline
Emergency Mode, a previously authenticated session may be retained after
logout, which could allow a subsequent user to be authenticated as the previous
user and gain unauthorised limited access to device functionality.
๐@cveNotify
A session management
vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware
uniFLOW Online. Under specific timing conditions during Service Offline
Emergency Mode, a previously authenticated session may be retained after
logout, which could allow a subsequent user to be authenticated as the previous
user and gain unauthorised limited access to device functionality.
๐@cveNotify
๐จ CVE-2000-0885
Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing" vulnerability. NOTE: It is highly likely that this candidate will be split into multiple candidates.
๐@cveNotify
Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing" vulnerability. NOTE: It is highly likely that this candidate will be split into multiple candidates.
๐@cveNotify
Docs
Microsoft Security Bulletin MS00-083 - Critical
๐จ CVE-2000-0887
named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by making a compressed zone transfer (ZXFR) request and performing a name service query on an authoritative record that is not cached, aka the "zxfr bug."
๐@cveNotify
named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by making a compressed zone transfer (ZXFR) request and performing a name service query on an authoritative record that is not cached, aka the "zxfr bug."
๐@cveNotify