← Back

CVE-2026-13129

nvd nist
Published: Jul 8, 2026Modified: Jul 9, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: 14984358-7092-470d-8f34-ade47a7658a2 (Secondary)

Description

When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form object when accessing the field property path. Eventually, the application crashes due to reading an invalid pointer.

Affected (7)

2 products
Pdf Editor
Pdf Reader
Configuration A
7 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Foxit
Up to 13.2.4.24048
From 14.0.0.33046 to 14.0.4.33508
From 2023.1.0.15510 to 2023.3.0.23028
From 2024.1.0.23997 to 2024.4.1.27687
From 2025.1.0.27937 to 2025.3.0.35737
From 2026.1.0.36452 to 2026.1.1.36485
Up to 2026.1.1.36485
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (1)

Source: 14984358-7092-470d-8f34-ade47a7658a2
Vendor Advisory

Timeline

No history available yet.