← Back

CVE-2025-66499

nvd nist
Published: Dec 19, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: 14984358-7092-470d-8f34-ade47a7658a2 (Secondary)

Description

A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data. An integer overflow in the calculation of the image buffer size may occur, potentially allowing a remote attacker to execute arbitrary code.

Affected (12)

2 products
Pdf Editor
Pdf Reader
Configuration A
6 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Foxit
Up to 13.2.1.23955
From 14.0.0.33046 to 14.0.1.33197
From 2023.1.0.15510 to 2023.3.0.23028
From 2024.1.0.23997 to 2024.4.1.27687
From 2025.1.0.27937 to 2025.2.1.33197
Up to 2025.2.1.33197
Running on/withPlatform Versions
Microsoft
Windows
All versions
Configuration B
6 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Foxit
Up to 13.2.1.63315
From 14.0.0.33046 to 14.0.1.69005
From 2023.1.0.15510 to 2023.3.0.63083
From 2024.1.0.23997 to 2024.4.1.66479
From 2025.1.0.27937 to 2025.2.1.69005
Up to 2025.2.1.69005
Running on/withPlatform Versions
Apple
Macos
All versions

References (1)

Source: 14984358-7092-470d-8f34-ade47a7658a2
Vendor Advisory

Timeline

No history available yet.