Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-57244

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verification, resulting in the failure of the control pointer during the traversal process. After the pointer fails, it still continues to dereference, causing the application to crash.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Версия до 13.2.4.24048 (включая)
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Версия от 14.0.0.33046 (включая) до 14.0.4.33508 (включая)
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Версия от 2023.1.0.15510 (включая) до 2023.3.0.23028 (включая)
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Версия от 2024.1.0.23997 (включая) до 2024.4.1.27687 (включая)
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Версия от 2025.1.0.27937 (включая) до 2025.3.0.35737 (включая)
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Версия от 2026.1.0.36452 (включая) до 2026.1.1.36485 (включая)
cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*
Версия до 2026.1.1.36485 (включая)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

Одно из

cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Версия до 13.2.3.63444 (включая)
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Версия от 14.0.0.68868 (включая) до 14.0.3.69295 (включая)
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Версия от 2023.1.0.55583 (включая) до 2023.3.0.63083 (включая)
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Версия от 2024.1.0.63682 (включая) до 2024.4.1.66479 (включая)
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Версия от 2025.1.0.66692 (включая) до 2025.3.0.69570 (включая)
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
Версия от 2026.1.0.70169 (включая) до 2026.1.1.70276 (включая)
cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*
Версия до 2026.1.1.70276 (включая)
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

EPSS

Процентиль: 7%
0.0017
Низкий

7.8 High

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 7.8
github
2 месяца назад

After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verification, resulting in the failure of the control pointer during the traversal process. After the pointer fails, it still continues to dereference, causing the application to crash.

EPSS

Процентиль: 7%
0.0017
Низкий

7.8 High

CVSS3

Дефекты

CWE-416