Описание
When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlying native object is damaged, but the application does not perform validation. The function call on the damaged object leads to the application crashing.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 13.2.4.24048 (включая)Версия от 14.0.0.33046 (включая) до 14.0.4.33508 (включая)Версия от 2023.1.0.15510 (включая) до 2023.3.0.23028 (включая)Версия от 2024.1.0.23997 (включая) до 2024.4.1.27687 (включая)Версия от 2025.1.0.27937 (включая) до 2025.3.0.35737 (включая)Версия от 2026.1.0.36452 (включая) до 2026.1.1.36485 (включая)Версия до 2026.1.1.36485 (включая)
Одновременно
Одно из
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Конфигурация 2Версия до 13.2.3.63444 (включая)Версия от 14.0.0.68868 (включая) до 14.0.3.69295 (включая)Версия от 2023.1.0.55583 (включая) до 2023.3.0.63083 (включая)Версия от 2024.1.0.63682 (включая) до 2024.4.1.66479 (включая)Версия от 2025.1.0.66692 (включая) до 2025.3.0.69570 (включая)Версия от 2026.1.0.70169 (включая) до 2026.1.1.70276 (включая)Версия до 2026.1.1.70276 (включая)
Одновременно
Одно из
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
EPSS
Процентиль: 2%
0.00116
Низкий
7.8 High
CVSS3
Дефекты
CWE-416
Связанные уязвимости
CVSS3: 7.8
github
26 дней назад
When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlying native object is damaged, but the application does not perform validation. The function call on the damaged object leads to the application crashing.
EPSS
Процентиль: 2%
0.00116
Низкий
7.8 High
CVSS3
Дефекты
CWE-416