When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form object when accessing the field property path. Eventually, the application crashes due to reading an invalid pointer.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 13.2.4.24048CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* | ||
>= 14.0.0.33046, <= 14.0.4.33508CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* | ||
>= 2023.1.0.15510, <= 2023.3.0.23028CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* | ||
>= 2024.1.0.23997, <= 2024.4.1.27687CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* | ||
>= 2025.1.0.27937, <= 2025.3.0.35737CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.