← Vulnerability feed

Vulnerability record · CVE-2021-38564 · published 11 August 2021

CVE-2021-38564: Foxitsoftware pdf editor out-of-bounds read vulnerability

Foxitsoftware · Pdf Editor

An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It allows an out-of-bounds read via util.scand.

9.1 CVSS 3.1 Critical EPSS 1.1% · top 36.1% CWE-125 · Out-of-bounds read
9.1CVSS 3.1 base score, v2 6.4
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It allows an out-of-bounds read via util.scand.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-38564 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-38563Foxit pdf reader vulnerabilityAn issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It mishandles situations in which an array size (derived from…EPSS 1.1%7.8CVE-2021-34849Foxit pdf reader use after free vulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is …EPSS 2.9%7.8CVE-2021-34850Foxit pdf reader use after free vulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is …EPSS 38%7.8CVE-2021-34851Foxit pdf reader use after free vulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is …EPSS 4.0%7.8CVE-2021-34852Foxit pdf reader use after free vulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is …EPSS 4.0%7.8CVE-2021-34853Foxit pdf reader use after free vulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is …EPSS 4.0%7.8CVE-2021-34838Foxit pdf reader use after free vulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is …EPSS 3.8%7.8CVE-2021-34839Foxit pdf reader use after free vulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is …EPSS 4.0%

Source: NIST National Vulnerability Database (record CVE-2021-38564), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.