CVE-2026-3780
- EPSS 0.12%
- Veröffentlicht 01.04.2026 01:40:33
- Zuletzt bearbeitet 28.04.2026 14:14:57
The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and ...
CVE-2026-3778
- EPSS 0.1%
- Veröffentlicht 01.04.2026 01:40:31
- Zuletzt bearbeitet 14.04.2026 17:50:53
The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pages and annotations are crafted that reference each other in a loop, passing the document to APIs (e.g., SOAP) that perform deep tr...
CVE-2025-66499
- EPSS 0.29%
- Veröffentlicht 19.12.2025 07:16:03
- Zuletzt bearbeitet 23.12.2025 17:37:17
A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data. An integer overflow in the calculation of the image buffer size may occur, potentially allowing a remote attacker t...
CVE-2025-66496
- EPSS 0.21%
- Veröffentlicht 19.12.2025 07:16:02
- Zuletzt bearbeitet 23.12.2025 17:36:35
A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory ...
CVE-2025-66498
- EPSS 0.21%
- Veröffentlicht 19.12.2025 07:16:02
- Zuletzt bearbeitet 23.12.2025 17:37:08
A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing U3D data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory ...
CVE-2025-66497
- EPSS 0.21%
- Veröffentlicht 19.12.2025 07:16:02
- Zuletzt bearbeitet 23.12.2025 17:37:12
A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory ...
CVE-2025-66495
- EPSS 0.3%
- Veröffentlicht 19.12.2025 07:16:02
- Zuletzt bearbeitet 23.12.2025 17:36:27
A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows and MacOS. When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed...
CVE-2025-66494
- EPSS 0.3%
- Veröffentlicht 19.12.2025 07:16:02
- Zuletzt bearbeitet 23.12.2025 17:36:30
A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows. A PDF object managed by multiple parent objects could be freed while still being referenced, potentially allowing a remo...
CVE-2025-66493
- EPSS 0.3%
- Veröffentlicht 19.12.2025 07:16:01
- Zuletzt bearbeitet 23.12.2025 17:36:09
A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,14.0.1 and 13.2.1 on Windows . When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already...
CVE-2025-13941
- EPSS 0.19%
- Veröffentlicht 19.12.2025 02:16:04
- Zuletzt bearbeitet 23.12.2025 17:35:55
A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installation, incorrect file system permissions are assigned to resources used by the update service. A local attacker with low privileges ...