7.8

CVE-2026-57260

Medienbericht

Security vulnerability in Foxit PDF Editor/Reader — U3D Adobe Mesh Decompression (Type Confusion / Invalid Pointer Dereference)

The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly resolved a portion of the abnormal object as a pointer and used it as a valid address, ultimately causing the application to crash.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FoxitPdf Editor Version <= 13.2.4.24048
   MicrosoftWindows Version-
FoxitPdf Editor Version >= 14.0.0.33046 <= 14.0.4.33508
   MicrosoftWindows Version-
FoxitPdf Editor Version >= 2023.1.0.15510 <= 2023.3.0.23028
   MicrosoftWindows Version-
FoxitPdf Editor Version >= 2024.1.0.23997 <= 2024.4.1.27687
   MicrosoftWindows Version-
FoxitPdf Editor Version >= 2025.1.0.27937 <= 2025.3.0.35737
   MicrosoftWindows Version-
FoxitPdf Editor Version >= 2026.1.0.36452 <= 2026.1.1.36485
   MicrosoftWindows Version-
FoxitPdf Reader Version <= 2026.1.1.36485
   MicrosoftWindows Version-
FoxitPdf Editor Version <= 13.2.3.63444
   ApplemacOS Version-
FoxitPdf Editor Version >= 14.0.0.68868 <= 14.0.3.69295
   ApplemacOS Version-
FoxitPdf Editor Version >= 2023.1.0.55583 <= 2023.3.0.63083
   ApplemacOS Version-
FoxitPdf Editor Version >= 2024.1.0.63682 <= 2024.4.1.66479
   ApplemacOS Version-
FoxitPdf Editor Version >= 2025.1.0.66692 <= 2025.3.0.69570
   ApplemacOS Version-
FoxitPdf Editor Version >= 2026.1.0.70169 <= 2026.1.1.70276
   ApplemacOS Version-
FoxitPdf Reader Version <= 2026.1.1.70276
   ApplemacOS Version-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.067
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
14984358-7092-470d-8f34-ade47a7658a2 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
13.07.2026 17:25
https://www.foxit.com/support/security-bulletins.html
Vendor Advisory