CVE-2017-8059: Foxitsoftware Foxit PDF
High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.
Acceptance of invalid/self-signed TLS certificates in "Foxit PDF - PDF reader, editor, form, signature" before 5.4 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept login information (username/password), in addition to the static authentication token if the user is already logged in.
Affected products
- Foxitsoftware Foxit PDF: version 5.2.1 only; version 5.3.2 only
Published 2017-05-05. Last modified 2026-06-17.