Description
After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verification, resulting in the failure of the control pointer during the traversal process. After the pointer fails, it still continues to dereference, causing the application to crash.
Severity (CVSS)
| Base score | 7.8 |
|---|---|
| Severity | High |
| Version | CVSS 3.1 |
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| Provided by | CNA |
Weaknesses
- CWE-416 — CWE-416 Use after free
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Foxit Software Inc. | Foxit PDF Editor | Versions 2026.1.1 and earlier; Versions 14.0.4 and earlier; Versions 13.2.4 and earlier |
| Foxit Software Inc. | Foxit PDF Editor | Versions 2026.1.1 and earlier; Versions 14.0.3 and earlier; Versions 13.2.3 and earlier |
| Foxit Software Inc. | Foxit PDF Reader | Versions 2026.1.1 and earlier |
References
Generated from the official CVE List on 09 Jul 2026 07:08 UTC.