vciy

Foxit Reader: 88 records in one advisory

88 records announced together, published between 2019-10-03 and 2021-05-21, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://www.foxitsoftware.com/support/security-bulletins.php. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

No record in this batch is listed by CISA in held sources.

17 of 88 records name something of its own. For the other 71, held sources say the same thing about each.

Most commonly mapped weakness across the batch: CWE-416: Use After Free.

What this page does not cover

This batch is 88 of the 636 records that cite the same advisory. The other 548 are different findings announced alongside it.

380 of them are on the sibling batches linked below. The remaining 168 are grouped with nothing and have only their own record pages.

Other batches under the same advisory: foxitsoftware-security-bulletins-0463ca62e1, foxitsoftware-security-bulletins-52bff22065, foxitsoftware-security-bulletins-fd32fa6e8f

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

What this batch was researched, not held

Foxit Reader code execution records from 2019 to 2021, and who was left reporting them

The records in this group were published between 3 October 2019 and 21 May 2021, and they share one opening sentence: this vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader. That is the advisory template of Trend Micro's Zero Day Initiative, the same template a larger group at this anchor carries for the 2017 buying wave, so a shared shape here means a shared publisher. What marks this later window is the credit line. CVE-2019-13326, a member of this group, was published as ZDI-19-849 on 1 October 2019, after Foxit was notified on 16 July 2019, and its researcher line reads Anonymous. By the May 2021 batch the programme was publishing Foxit advisories credited to its own staff: ZDI-21-527, for CVE-2021-31470, was reported to Foxit on 20 January 2021, published on 7 May 2021 and credited to Mat Powell of Trend Micro Zero Day Initiative. Both advisories carry a second template sentence, that the target must visit a malicious page or open a malicious file. Threatpost reported on 3 October 2019 that Foxit Reader 9.7 fixed eight high severity flaws, seven of them reported through the Zero Day Initiative and one by Cisco Talos, and that Foxit had patched over 100 vulnerabilities the year before.

These records were published together because one programme wrote and released them, not because they are one flaw. Each was reported on its own date, months apart in places, and the shared sentence says nothing about whether any two of them touch the same code or are closed by the same Foxit release.

2019-07-16CVE-2019-13326, a member of this group, is reported to Foxit through the Zero Day Initiative
2019-10-01Advisory ZDI-19-849 is published for CVE-2019-13326, with the researcher recorded only as Anonymous
2019-10-03Threatpost reports Foxit Reader 9.7 fixing eight high severity flaws, seven from the Zero Day Initiative and one from Cisco Talos
2021-01-20CVE-2021-31470, a Foxit finding from the same stream in this window, is reported to Foxit by the programme's own researcher
2021-05-07Advisory ZDI-21-527 is published, credited to Mat Powell of Trend Micro Zero Day Initiative

The credit line is the gap here. Anonymous is a real entry in this programme's advisories, so a record marked that way cannot tell you whether an outside researcher sold the report or the programme's own staff found it. The advisories name the Foxit build that was vulnerable, 9.5.0.20723 in the 2019 case, but not the release that carried the fix, so a reader who wants to know what to upgrade to has to go back to Foxit's bulletin index.

Written from zerodayinitiative.com, zerodayinitiative.com, threatpost.com, foxitsoftware.com, foxit.com. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at medium confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2019-13319no title heldCWE-416: Use After Free
CVE-2019-13320no title heldCWE-416: Use After Free
CVE-2019-13323no title heldCWE-787: Out-of-bounds Write
CVE-2019-13324no title heldCWE-125: Out-of-bounds Read
CVE-2019-13325no title heldCWE-125: Out-of-bounds Read
CVE-2019-13326no title heldCWE-416: Use After Free
CVE-2019-13327no title heldCWE-416: Use After Free
CVE-2019-13328no title heldCWE-416: Use After Free
CVE-2019-13329no title heldCWE-843: Access of Resource Using Incompatible…
CVE-2019-13330no title heldCWE-843: Access of Resource Using Incompatible…
CVE-2019-13331no title heldCWE-125: Out-of-bounds Read
CVE-2019-13332no title heldCWE-416: Use After Free
CVE-2019-17139html2pdfCWE-787: Out-of-bounds Write
CVE-2019-17140no title heldCWE-416: Use After Free
CVE-2019-17141no title heldCWE-416: Use After Free
CVE-2019-17142listboxCWE-416: Use After Free
CVE-2019-6774deleteitematCWE-416: Use After Free
CVE-2019-6775no title heldCWE-416: Use After Free
CVE-2019-6776no title heldCWE-416: Use After Free
CVE-2020-10889duplicatepagesCWE-843: Access of Resource Using Incompatible…
CVE-2020-10890no title heldCWE-352: Cross-Site Request Forgery (CSRF)
CVE-2020-10891saveCWE-843: Access of Resource Using Incompatible…
CVE-2020-10892no title heldCWE-352: Cross-Site Request Forgery (CSRF)
CVE-2020-10893no title heldCWE-787: Out-of-bounds Write
CVE-2020-10895no title heldCWE-125: Out-of-bounds Read
CVE-2020-10896no title heldCWE-122: Heap-based Buffer Overflow
CVE-2020-10897no title heldCWE-787: Out-of-bounds Write
CVE-2020-10898no title heldCWE-125: Out-of-bounds Read
CVE-2020-10899no title heldCWE-416: Use After Free
CVE-2020-10900no title heldCWE-416: Use After Free
CVE-2020-10902no title heldCWE-125: Out-of-bounds Read
CVE-2020-10904no title heldCWE-787: Out-of-bounds Write
CVE-2020-10906no title heldCWE-416: Use After Free
CVE-2020-10907widgetsCWE-416: Use After Free
CVE-2020-10908exportCWE-843: Access of Resource Using Incompatible…
CVE-2020-10909addwatermarkCWE-843: Access of Resource Using Incompatible…
CVE-2020-10910rotatepageCWE-843: Access of Resource Using Incompatible…
CVE-2020-10911getfieldvalueCWE-843: Access of Resource Using Incompatible…
CVE-2020-10912setfieldvalueCWE-843: Access of Resource Using Incompatible…
CVE-2020-10913ocrandexporttoexcelCWE-843: Access of Resource Using Incompatible…
CVE-2020-17410no title heldCWE-416: Use After Free
CVE-2020-17412no title heldCWE-787: Out-of-bounds Write
CVE-2020-17413no title heldCWE-121: Stack-based Buffer Overflow
CVE-2020-17416no title heldCWE-787: Out-of-bounds Write
CVE-2020-17417no title heldCWE-416: Use After Free
CVE-2020-8844coverttopdfCWE-190: Integer Overflow or Wraparound
CVE-2020-8847no title heldCWE-787: Out-of-bounds Write
CVE-2020-8848no title heldCWE-787: Out-of-bounds Write
CVE-2020-8849no title heldCWE-787: Out-of-bounds Write
CVE-2020-8850no title heldCWE-787: Out-of-bounds Write
CVE-2020-8851no title heldCWE-787: Out-of-bounds Write
CVE-2020-8853no title heldCWE-787: Out-of-bounds Write
CVE-2020-8854no title heldCWE-787: Out-of-bounds Write
CVE-2020-8855fxhtml2pdf.exe moduleCWE-416: Use After Free
CVE-2020-8857no title heldCWE-416: Use After Free
CVE-2020-8869no title heldCWE-121: Stack-based Buffer Overflow
CVE-2020-8870gettifpaletteCWE-125: Out-of-bounds Read
CVE-2020-8878no title heldCWE-787: Out-of-bounds Write
CVE-2020-8880no title heldCWE-125: Out-of-bounds Read
CVE-2020-8881no title heldCWE-416: Use After Free
CVE-2020-8882no title heldCWE-824: Access of Uninitialized Pointer
CVE-2021-27261no title heldCWE-125: Out-of-bounds Read
CVE-2021-27267no title heldCWE-416: Use After Free
CVE-2021-27268no title heldCWE-416: Use After Free
CVE-2021-27269no title heldCWE-787: Out-of-bounds Write
CVE-2021-27270no title heldCWE-125: Out-of-bounds Read
CVE-2021-27271no title heldCWE-125: Out-of-bounds Read
CVE-2021-31441no title heldCWE-416: Use After Free
CVE-2021-31442no title heldCWE-787: Out-of-bounds Write
CVE-2021-31449no title heldCWE-415: Double Free
CVE-2021-31450no title heldCWE-416: Use After Free
CVE-2021-31451no title heldCWE-416: Use After Free
CVE-2021-31452no title heldCWE-787: Out-of-bounds Write
CVE-2021-31453no title heldCWE-416: Use After Free
CVE-2021-31454decimal leaddigits decimalCWE-122: Heap-based Buffer Overflow
CVE-2021-31455no title heldCWE-416: Use After Free
CVE-2021-31456no title heldCWE-416: Use After Free
CVE-2021-31457no title heldCWE-416: Use After Free
CVE-2021-31458no title heldCWE-416: Use After Free
CVE-2021-31459no title heldCWE-416: Use After Free
CVE-2021-31460no title heldCWE-416: Use After Free
CVE-2021-31461app.mediaCWE-843: Access of Resource Using Incompatible…
CVE-2021-31465no title heldCWE-787: Out-of-bounds Write
CVE-2021-31466no title heldCWE-125: Out-of-bounds Read
CVE-2021-31468no title heldCWE-125: Out-of-bounds Read
CVE-2021-31470no title heldCWE-416: Use After Free
CVE-2021-31472no title heldCWE-787: Out-of-bounds Write
CVE-2021-31473no title heldCWE-787: Out-of-bounds Write

88 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.