CVE-2026-5939
- EPSS 0.11%
- Veröffentlicht 27.04.2026 11:00:29
- Zuletzt bearbeitet 29.04.2026 17:28:10
A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution.
CVE-2026-5941
- EPSS 0.17%
- Veröffentlicht 27.04.2026 11:00:25
- Zuletzt bearbeitet 29.04.2026 17:24:15
Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form field hierarchies, leading to invalid memory writes and program crashes during internal data structure construction.
CVE-2026-3774
- EPSS 0.11%
- Veröffentlicht 01.04.2026 01:40:39
- Zuletzt bearbeitet 10.04.2026 01:36:58
The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, annotations, or optional content groups (OCGs) immediately before or after redaction, encryption, or printing. These script‑driven up...
CVE-2026-3775
- EPSS 0.25%
- Veröffentlicht 01.04.2026 01:40:36
- Zuletzt bearbeitet 14.04.2026 17:56:31
The application's update service, when checking for updates, loads certain system libraries from a search path that includes directories writable by low‑privileged users and is not strictly restricted to trusted system locations. Because these librar...
CVE-2026-3776
- EPSS 0.1%
- Veröffentlicht 01.04.2026 01:40:35
- Zuletzt bearbeitet 14.04.2026 17:55:57
The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp annotation missing its AP entry, the code continues to dereference the associated object without ...
CVE-2026-3780
- EPSS 0.12%
- Veröffentlicht 01.04.2026 01:40:33
- Zuletzt bearbeitet 28.04.2026 14:14:57
The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and ...
CVE-2026-3778
- EPSS 0.1%
- Veröffentlicht 01.04.2026 01:40:31
- Zuletzt bearbeitet 14.04.2026 17:50:53
The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pages and annotations are crafted that reference each other in a loop, passing the document to APIs (e.g., SOAP) that perform deep tr...
CVE-2026-3779
- EPSS 0.31%
- Veröffentlicht 01.04.2026 01:40:29
- Zuletzt bearbeitet 28.04.2026 14:15:34
The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arb...
CVE-2026-3777
- EPSS 0.12%
- Veröffentlicht 01.04.2026 01:40:27
- Zuletzt bearbeitet 14.04.2026 17:54:52
The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and page state. When a script modifies the zoom property and then triggers a page change, the original vie...
CVE-2025-66499
- EPSS 0.29%
- Veröffentlicht 19.12.2025 07:16:03
- Zuletzt bearbeitet 23.12.2025 17:37:17
A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data. An integer overflow in the calculation of the image buffer size may occur, potentially allowing a remote attacker t...