Описание
The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related objects within the application to lose synchronization; however, the renderer still trusts the outdated page count, and eventually the application crashes due to out-of-bounds access.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 13.2.4.24048 (включая)Версия от 14.0.0.33046 (включая) до 14.0.4.33508 (включая)Версия от 2023.1.0.15510 (включая) до 2023.3.0.23028 (включая)Версия от 2024.1.0.23997 (включая) до 2024.4.1.27687 (включая)Версия от 2025.1.0.27937 (включая) до 2025.3.0.35737 (включая)Версия от 2026.1.0.36452 (включая) до 2026.1.1.36485 (включая)Версия до 2026.1.1.36485 (включая)
Одновременно
Одно из
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
EPSS
Процентиль: 5%
0.00153
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-125
Связанные уязвимости
CVSS3: 6.1
github
2 месяца назад
The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related objects within the application to lose synchronization; however, the renderer still trusts the outdated page count, and eventually the application crashes due to out-of-bounds access.
EPSS
Процентиль: 5%
0.00153
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-125