Description

After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verification, resulting in the failure of the control pointer during the traversal process. After the pointer fails, it still continues to dereference, causing the application to crash.

Severity (CVSS)

Base score7.8
SeverityHigh
VersionCVSS 3.1
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Provided byCNA

Weaknesses

  • CWE-416 — CWE-416 Use after free

Affected products

VendorProductVersions
Foxit Software Inc.Foxit PDF EditorVersions 2026.1.1 and earlier; Versions 14.0.4 and earlier; Versions 13.2.4 and earlier
Foxit Software Inc.Foxit PDF EditorVersions 2026.1.1 and earlier; Versions 14.0.3 and earlier; Versions 13.2.3 and earlier
Foxit Software Inc.Foxit PDF ReaderVersions 2026.1.1 and earlier

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 09 Jul 2026 07:08 UTC.