CVE-2026-57244
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: 14984358-7092-470d-8f34-ade47a7658a2 (Secondary)
Description
After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verification, resulting in the failure of the control pointer during the traversal process. After the pointer fails, it still continues to dereference, causing the application to crash.
Affected (14)
Products: Foxit: Pdf Editor, Pdf Reader
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 13.2.4.24048 | |
| Up to 2026.1.1.36485 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 13.2.3.63444 | |
| Up to 2026.1.1.70276 |
| Running on/with | Platform Versions |
|---|---|
Apple Macos | All versions |
References (1)
Source: 14984358-7092-470d-8f34-ade47a7658a2
Vendor Advisory
Timeline
No history available yet.