Foxit Reader: 66 records in one advisory
66 records announced together, published between 2017-10-31 and 2019-06-03, every one of them citing the same advisory.
The advisory
Every record in this batch cites https://www.foxitsoftware.com/support/security-bulletins.php. That is the CNA's own reference, held in the index, and it is why these records are on one page.
What the records offer
No record in this batch publishes a fixed version in held sources.
No record in this batch is listed by CISA in held sources.
22 of 66 records name something of its own. For the other 44, held sources say the same thing about each.
Most commonly mapped weakness across the batch: CWE-125-Out-of-bounds Read.
What this page does not cover
This batch is 66 of the 636 records that cite the same advisory. The other 570 are different findings announced alongside it.
402 of them are on the sibling batches linked below. The remaining 168 are grouped with nothing and have only their own record pages.
Other batches under the same advisory: foxitsoftware-security-bulletins-52bff22065, foxitsoftware-security-bulletins-828fde758e, foxitsoftware-security-bulletins-fd32fa6e8f
The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.
What this batch was researched, not held
Foxit Reader records that all say something was disclosed, and none say what
Every record in this group opens with the same sentence: this vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. That sentence is the advisory template of Trend Micro's Zero Day Initiative, the programme that buys vulnerability reports and was the numbering authority for this stream of Foxit findings. A shared shape here means a shared publisher, not a shared defect. A larger group at the same anchor covers the 2017 buying wave that produced the volume; what is particular to these records is how hard this kind of finding is to make in the first place. Steven Seeley of Source Incite, writing in June 2018 about his own work on the same product in the same period, said he had found over 100 vulnerabilities in Foxit Reader and had built a WinDbg plugin called bridgit specifically to hunt uninitialised memory disclosure, because ordinary fuzzing does not catch it: the program keeps running, so there is no crash for a fuzzer to notice. That is his account of his own work, not a statement about who found the records here. Two findings in this stream do carry a named finder. CVE-2017-10942, in this group, is titled a PDF parsing out-of-bounds read information disclosure, was reported by Ashfaq Ansari of Project Srishti, reached Foxit on 18 May 2017 and was published as ZDI-17-455 on 7 July 2017. CVE-2017-14821, an identifier sitting next to two members of this group, is titled a JPEG2000 SIZ marker xTsiz out-of-bounds read information disclosure, was reported by kdot, reached Foxit on 10 August 2017 and was published on 14 November 2017.
Two records here can read word for word alike and still be unrelated flaws, found by different people months apart, because the opening sentence is the publisher's template. Nothing in that shared wording says the records touch the same code, and nothing in it says one Foxit release closes more than the record it was issued for.
A record here tells you that something was disclosed and never what. The body is two template sentences, the only technical detail sits in the advisory title, which names a file structure such as the SIZ marker of a JPEG2000 image, and neither says what memory was read, how much of it reached the attacker, or whether it was enough to be useful on its own. Many submissions in this stream are credited to Anonymous, so the group cannot tell you how many people are behind it.
Written from zerodayinitiative.com, zerodayinitiative.com, srcincite.io, foxitsoftware.com, foxit.com. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at medium confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.
Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.
66 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.