Foxit PDF Reader: 67 records in one advisory
67 records announced together, published between 2021-06-16 and 2023-03-29, every one of them citing the same advisory.
The advisory
Every record in this batch cites https://www.foxit.com/support/security-bulletins.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.
What the records offer
No record in this batch publishes a fixed version in held sources.
No record in this batch is listed by CISA in held sources.
3 of 67 records name something of its own. For the other 64, held sources say the same thing about each.
Most commonly mapped weakness across the batch: CWE-416: Use After Free.
What this page does not cover
This batch is 67 of the 329 records that cite the same advisory. The other 262 are different findings announced alongside it.
24 of them are on the sibling batch linked below. The remaining 238 are grouped with nothing and have only their own record pages.
Other batches under the same advisory: foxit-security-bulletins-a24f03d65a
The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.
What this batch was researched, not held
Foxit's bulletin index, where one brokered fuzzing programme is named 661 times
The reference on these records is Foxit's security bulletin index, a single page carrying 157 separate release entries. Across that page the name Trend Micro Zero Day Initiative, the programme that buys vulnerability reports and passes them to vendors, appears 661 times, and one of its own staff researchers, Mat Powell, is named 74 times. The Foxit PhantomPDF 10.1.5 entry of 26 August 2021 shows the shape of it. That entry lists 24 identifiers, and Foxit's own text gathers 16 of them into a single paragraph under one described cause: use-after-free crashes "when handling the annotation objects in certain PDF files if the same Annotation dictionary is referenced in the page structures for different pages". Foxit credits that paragraph to Xu Peng of the University of Chinese Academy of Sciences and Wang Yanhao of QiAnXin Technology Research Institute working with Trend Micro Zero Day Initiative, and to Mat Powell of the same programme. The other paragraphs in the same entry name entirely different people: Aleksandar Nikolic of Cisco Talos, Hou JingYi, and Xinyu Wan, Yiwei Zhang and Wei You of Renmin University of China.
These records share a link to one index page and nothing else, and they span years of separate Foxit releases. Where Foxit's own text groups several identifiers under one described cause, that grouping is Foxit's statement about the identifiers it names in that paragraph, and it says nothing about the rest.
The index is a running list of releases with no mapping from an identifier to a release, so it cannot tell you which release first fixed the record you are reading. Foxit also writes in prose paragraphs rather than one entry per identifier, so where a paragraph lists sixteen numbers there is no way to know which number is which crash, which code path, or which of the named reporters found it.
Written from foxit.com. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.
Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.
67 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.