Описание
After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verification, resulting in the failure of the control pointer during the traversal process. After the pointer fails, it still continues to dereference, causing the application to crash.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 13.2.4.24048 (включая)Версия от 14.0.0.33046 (включая) до 14.0.4.33508 (включая)Версия от 2023.1.0.15510 (включая) до 2023.3.0.23028 (включая)Версия от 2024.1.0.23997 (включая) до 2024.4.1.27687 (включая)Версия от 2025.1.0.27937 (включая) до 2025.3.0.35737 (включая)Версия от 2026.1.0.36452 (включая) до 2026.1.1.36485 (включая)Версия до 2026.1.1.36485 (включая)
Одновременно
Одно из
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Конфигурация 2Версия до 13.2.3.63444 (включая)Версия от 14.0.0.68868 (включая) до 14.0.3.69295 (включая)Версия от 2023.1.0.55583 (включая) до 2023.3.0.63083 (включая)Версия от 2024.1.0.63682 (включая) до 2024.4.1.66479 (включая)Версия от 2025.1.0.66692 (включая) до 2025.3.0.69570 (включая)Версия от 2026.1.0.70169 (включая) до 2026.1.1.70276 (включая)Версия до 2026.1.1.70276 (включая)
Одновременно
Одно из
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
EPSS
Процентиль: 7%
0.0017
Низкий
7.8 High
CVSS3
Дефекты
CWE-416
Связанные уязвимости
CVSS3: 7.8
github
2 месяца назад
After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verification, resulting in the failure of the control pointer during the traversal process. After the pointer fails, it still continues to dereference, causing the application to crash.
EPSS
Процентиль: 7%
0.0017
Низкий
7.8 High
CVSS3
Дефекты
CWE-416