7.8
CVE-2026-91795
- EPSS 0.09%
- Veröffentlicht 23.09.2026 07:51:06
- Zuletzt bearbeitet 08.10.2026 13:48:36
- Erkennungen
Foxit PDF Editor/Reader FileOpen Uninitialized Variable Remote Code Execution Vulnerability
Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files. This could leave an internal pointer in an invalid state, resulting in chained read and write access violations and potentially enabling arbitrary code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Foxit ≫ Pdf Editor Version <= 13.2.5.63482
Foxit ≫ Pdf Editor Version >= 14.0.0.33046 <= 14.0.7.33751
Foxit ≫ Pdf Editor Version >= 2023.1.0.15510 <= 2023.3.0.23028
Foxit ≫ Pdf Editor Version >= 2024.1.0.23997 <= 2024.4.1.27687
Foxit ≫ Pdf Editor Version >= 2025.1.0.27937 <= 2025.3.0.35737
Foxit ≫ Pdf Editor Version >= 2026.1.0.36452 <= 2026.2.0.39747
Foxit ≫ Pdf Reader Version <= 2026.2.0.39747
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.09% | 0.003 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 14984358-7092-470d-8f34-ade47a7658a2 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-822 Untrusted Pointer Dereference
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
https://www.foxit.com/support/security-bulletins.html