The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the invalidation of the page objects. However, the thumbnails still use the invalid page objects, ultimately causing the application to crash.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HFoxit Pdf Editor
APPFoxit≤ 13.2.4.2404814.0.0.33046 – 14.0.4.335082023.1.0.15510 – 2023.3.0.230282024.1.0.23997 – 2024.4.1.276872025.1.0.27937 – 2025.3.0.357372026.1.0.36452 – 2026.1.1.36485Foxit Pdf Reader
APPFoxit≤ 2026.1.1.36485Microsoft Windows
OSMicrosoftall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
Related vulnerabilities
CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
CVE-2024-7262CRITICAL9.3⚠ KEVPL ✓same product
Path Traversal w Kingsoft WPS Office — ładowanie dowolnej biblioteki Windows
CVE-2024-4577CRITICAL9.8⚠ KEVPL ✓same product
PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit