vciy

Foxit PDF Reader: 67 records in one advisory

67 records announced together, published between 2021-06-16 and 2023-03-29, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://www.foxit.com/support/security-bulletins.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

No record in this batch is listed by CISA in held sources.

3 of 67 records name something of its own. For the other 64, held sources say the same thing about each.

Most commonly mapped weakness across the batch: CWE-416: Use After Free.

What this page does not cover

This batch is 67 of the 329 records that cite the same advisory. The other 262 are different findings announced alongside it.

24 of them are on the sibling batch linked below. The remaining 238 are grouped with nothing and have only their own record pages.

Other batches under the same advisory: foxit-security-bulletins-a24f03d65a

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

What this batch was researched, not held

Foxit's bulletin index, where one brokered fuzzing programme is named 661 times

The reference on these records is Foxit's security bulletin index, a single page carrying 157 separate release entries. Across that page the name Trend Micro Zero Day Initiative, the programme that buys vulnerability reports and passes them to vendors, appears 661 times, and one of its own staff researchers, Mat Powell, is named 74 times. The Foxit PhantomPDF 10.1.5 entry of 26 August 2021 shows the shape of it. That entry lists 24 identifiers, and Foxit's own text gathers 16 of them into a single paragraph under one described cause: use-after-free crashes "when handling the annotation objects in certain PDF files if the same Annotation dictionary is referenced in the page structures for different pages". Foxit credits that paragraph to Xu Peng of the University of Chinese Academy of Sciences and Wang Yanhao of QiAnXin Technology Research Institute working with Trend Micro Zero Day Initiative, and to Mat Powell of the same programme. The other paragraphs in the same entry name entirely different people: Aleksandar Nikolic of Cisco Talos, Hou JingYi, and Xinyu Wan, Yiwei Zhang and Wei You of Renmin University of China.

These records share a link to one index page and nothing else, and they span years of separate Foxit releases. Where Foxit's own text groups several identifiers under one described cause, that grouping is Foxit's statement about the identifiers it names in that paragraph, and it says nothing about the rest.

2021-08-26Foxit releases PhantomPDF 10.1.5, whose index entry lists 24 identifiers across several described issues.

The index is a running list of releases with no mapping from an identifier to a release, so it cannot tell you which release first fixed the record you are reading. Foxit also writes in prose paragraphs rather than one entry per identifier, so where a paragraph lists sixteen numbers there is no way to know which number is which crash, which code path, or which of the named reporters found it.

Written from foxit.com. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2021-31476no title heldCWE-843: Access of Resource Using Incompatible…
CVE-2021-34831no title heldCWE-416: Use After Free
CVE-2021-34832no title heldCWE-416: Use After Free
CVE-2021-34833no title heldCWE-416: Use After Free
CVE-2021-34834no title heldCWE-416: Use After Free
CVE-2021-34835no title heldCWE-416: Use After Free
CVE-2021-34836no title heldCWE-416: Use After Free
CVE-2021-34837no title heldCWE-416: Use After Free
CVE-2021-34838no title heldCWE-416: Use After Free
CVE-2021-34839no title heldCWE-416: Use After Free
CVE-2021-34840no title heldCWE-416: Use After Free
CVE-2021-34841no title heldCWE-416: Use After Free
CVE-2021-34842no title heldCWE-416: Use After Free
CVE-2021-34843no title heldCWE-416: Use After Free
CVE-2021-34844no title heldCWE-416: Use After Free
CVE-2021-34845no title heldCWE-416: Use After Free
CVE-2021-34846no title heldCWE-416: Use After Free
CVE-2021-34847no title heldCWE-416: Use After Free
CVE-2021-34848no title heldCWE-416: Use After Free
CVE-2021-34849no title heldCWE-416: Use After Free
CVE-2021-34850no title heldCWE-416: Use After Free
CVE-2021-34851no title heldCWE-416: Use After Free
CVE-2021-34852no title heldCWE-416: Use After Free
CVE-2021-34853no title heldCWE-416: Use After Free
CVE-2022-24356onmouseexitCWE-125: Out-of-bounds Read
CVE-2022-24357no title heldCWE-416: Use After Free
CVE-2022-24358no title heldCWE-125: Out-of-bounds Read
CVE-2022-24359no title heldCWE-416: Use After Free
CVE-2022-24360no title heldCWE-416: Use After Free
CVE-2022-24361no title heldCWE-787: Out-of-bounds Write
CVE-2022-24362no title heldCWE-416: Use After Free
CVE-2022-24363no title heldCWE-416: Use After Free
CVE-2022-24364no title heldCWE-416: Use After Free
CVE-2022-24365no title heldCWE-416: Use After Free
CVE-2022-24366no title heldCWE-416: Use After Free
CVE-2022-24367no title heldCWE-416: Use After Free
CVE-2022-24369no title heldCWE-787: Out-of-bounds Write
CVE-2022-24907no title heldCWE-125: Out-of-bounds Read
CVE-2022-24908no title heldCWE-125: Out-of-bounds Read
CVE-2022-24971no title heldCWE-125: Out-of-bounds Read
CVE-2022-28669no title heldCWE-416: Use After Free
CVE-2022-28671no title heldCWE-416: Use After Free
CVE-2022-28672no title heldCWE-416: Use After Free
CVE-2022-28673no title heldCWE-416: Use After Free
CVE-2022-28674no title heldCWE-416: Use After Free
CVE-2022-28675no title heldCWE-416: Use After Free
CVE-2022-28676no title heldCWE-416: Use After Free
CVE-2022-28677no title heldCWE-416: Use After Free
CVE-2022-28678no title heldCWE-416: Use After Free
CVE-2022-28679no title heldCWE-416: Use After Free
CVE-2022-28680no title heldCWE-416: Use After Free
CVE-2022-28682no title heldCWE-125: Out-of-bounds Read
CVE-2022-28683no title heldCWE-416: Use After Free
CVE-2022-37377optimizationsCWE-843: Access of Resource Using Incompatible…
CVE-2022-37378functionsCWE-416: Use After Free
CVE-2022-37381no title heldCWE-416: Use After Free
CVE-2022-37384no title heldCWE-416: Use After Free
CVE-2022-37385no title heldCWE-416: Use After Free
CVE-2022-37387no title heldCWE-416: Use After Free
CVE-2022-37388no title heldCWE-125: Out-of-bounds Read
CVE-2022-37389no title heldCWE-416: Use After Free
CVE-2022-37390no title heldCWE-416: Use After Free
CVE-2022-37391no title heldCWE-416: Use After Free
CVE-2022-43637no title heldCWE-416: Use After Free
CVE-2022-43638no title heldCWE-416: Use After Free
CVE-2022-43639no title heldCWE-416: Use After Free
CVE-2022-43649no title heldCWE-416: Use After Free

67 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.