Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-32451

Опубликовано: 13 авг. 2025
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

A memory corruption vulnerability exists in Foxit Reader 2025.1.0.27937 due to the use of an uninitialized pointer. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:foxit:pdf_reader:2025.1.0.27937:*:*:*:*:*:*:*

EPSS

Процентиль: 15%
0.00049
Низкий

8.8 High

CVSS3

Дефекты

CWE-824

Связанные уязвимости

CVSS3: 8.8
github
около 1 месяца назад

A memory corruption vulnerability exists in Foxit Reader 2025.1.0.27937 due to the use of an uninitialized pointer. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

EPSS

Процентиль: 15%
0.00049
Низкий

8.8 High

CVSS3

Дефекты

CWE-824