CVE-2025-66494
- EPSS 0.3%
- Veröffentlicht 19.12.2025 07:16:02
- Zuletzt bearbeitet 23.12.2025 17:36:30
A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows. A PDF object managed by multiple parent objects could be freed while still being referenced, potentially allowing a remo...
CVE-2025-66495
- EPSS 0.3%
- Veröffentlicht 19.12.2025 07:16:02
- Zuletzt bearbeitet 23.12.2025 17:36:27
A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows and MacOS. When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed...
CVE-2025-66496
- EPSS 0.21%
- Veröffentlicht 19.12.2025 07:16:02
- Zuletzt bearbeitet 23.12.2025 17:36:35
A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory ...
CVE-2025-66497
- EPSS 0.21%
- Veröffentlicht 19.12.2025 07:16:02
- Zuletzt bearbeitet 23.12.2025 17:37:12
A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory ...
CVE-2025-66498
- EPSS 0.21%
- Veröffentlicht 19.12.2025 07:16:02
- Zuletzt bearbeitet 23.12.2025 17:37:08
A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing U3D data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory ...
CVE-2025-66493
- EPSS 0.3%
- Veröffentlicht 19.12.2025 07:16:01
- Zuletzt bearbeitet 23.12.2025 17:36:09
A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,14.0.1 and 13.2.1 on Windows . When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already...
CVE-2025-13941
- EPSS 0.19%
- Veröffentlicht 19.12.2025 02:16:04
- Zuletzt bearbeitet 23.12.2025 17:35:55
A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installation, incorrect file system permissions are assigned to resources used by the update service. A local attacker with low privileges ...
CVE-2025-55307
- EPSS 0.18%
- Veröffentlicht 11.12.2025 00:00:00
- Zuletzt bearbeitet 06.01.2026 14:39:54
An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. Opening a malicious PDF containing a crafted JavaScript call to search.query() with a crafted cDIPath parameter (e.g., "/") may cause an out-of-bounds rea...
CVE-2025-59802
- EPSS 0.31%
- Veröffentlicht 11.12.2025 00:00:00
- Zuletzt bearbeitet 18.12.2025 21:31:21
Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via OCG. When Optional Content Groups (OCG) are supported, the state property of an OCG is runtime-only and not included in the digital signature computation buffer. An attacker can...
CVE-2025-59803
- EPSS 0.18%
- Veröffentlicht 11.12.2025 00:00:00
- Zuletzt bearbeitet 15.12.2025 20:17:46
Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker can embed triggers (e.g., JavaScript) in a PDF document that execute during the signing process. When a signer reviews the document, the content appears no...