Foxit PDF Reader version 9.0.1.1049 has a use-after-free vulnerability in the Text Annotations component and the TypedArray's use uninitialized pointers. The vulnerabilities can be combined to leak a vtable memory address, which can be adjusted to point to the base address of the executable. A ROP chain can be constructed that will execute when Foxit Reader performs the UAF.
328a4999829d5eb3b12ffaeb666a27977fb72410e1a96f44c840761020615f82
Foxit Reader version 9.0.1.1049 remote code execution exploit with DEP bypass on heap with shellcode.
856e0ae7837f47fd2c2dc103ebfc93a1ff926dd85dc2d5bd3c30b11f47517528
Foxit Reader version 9.0.1.1049 suffers from a remote code execution vulnerability.
bf72b6326ebb4c4437a3f788a33ad75112bc77e87bca036144808a27a94871f6