CVE-2026-57250
- EPSS 0.12%
- Veröffentlicht 08.07.2026 07:36:01
- Zuletzt bearbeitet 09.07.2026 13:10:49
When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlying native object is damaged, but the application does not perform validation. The function call on the damaged object leads to the...
CVE-2026-57256
- EPSS 0.13%
- Veröffentlicht 08.07.2026 07:35:59
- Zuletzt bearbeitet 09.07.2026 18:16:54
When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and this operation is repeated after the form is reset. During this process, the application failed to adequately verify the validity of ...
CVE-2026-57257
- EPSS 0.11%
- Veröffentlicht 08.07.2026 07:35:58
- Zuletzt bearbeitet 09.07.2026 14:25:57
During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-of-bounds read of the entity array. As a result, the application crashes.
CVE-2026-57258
- EPSS 0.11%
- Veröffentlicht 08.07.2026 07:35:56
- Zuletzt bearbeitet 09.07.2026 14:30:06
The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underlying array contains elements and reads them, leading to out-of-bounds reads and application crashes.
CVE-2026-57260
- EPSS 0.17%
- Veröffentlicht 08.07.2026 07:35:55
- Zuletzt bearbeitet 09.07.2026 11:32:15
The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly resolved a portion of the abnormal object as a pointer and used it as a valid address, ultimately causing the application to crash.
CVE-2026-5937
- EPSS 0.1%
- Veröffentlicht 27.04.2026 11:00:42
- Zuletzt bearbeitet 29.04.2026 17:31:29
Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "std::invalid_argument" exception, ultimately causing the program to terminate.
CVE-2026-5938
- EPSS 0.1%
- Veröffentlicht 27.04.2026 11:00:38
- Zuletzt bearbeitet 29.04.2026 17:29:29
Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service.
CVE-2026-5940
- EPSS 0.17%
- Veröffentlicht 27.04.2026 11:00:36
- Zuletzt bearbeitet 29.04.2026 17:26:50
Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes.
CVE-2026-5942
- EPSS 0.18%
- Veröffentlicht 27.04.2026 11:00:33
- Zuletzt bearbeitet 29.04.2026 17:18:37
Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to access invalidated objects and crash the program.
CVE-2026-5943
- EPSS 0.18%
- Veröffentlicht 27.04.2026 11:00:31
- Zuletzt bearbeitet 29.04.2026 17:18:04
Document structural anomalies caused inconsistencies between page element relationships and internal index states. When scripts triggered document modifications, object reference validity was not properly maintained, leading to a crash when accessing...