A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data. An integer overflow in the calculation of the image buffer size may occur, potentially allowing a remote attacker to execute arbitrary code.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 19 Dec 2025 07:15:00 +0000

Type Values Removed Values Added
Description A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data. An integer overflow in the calculation of the image buffer size may occur, potentially allowing a remote attacker to execute arbitrary code.
Title Foxit PDF Reader PDF Parsing Heap-Based Buffer Overflow Remote Code Execution Vulnerability
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2025-12-19T07:11:50.238Z

Reserved: 2025-12-03T01:33:55.298Z

Link: CVE-2025-66499

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-19T07:16:03.197

Modified: 2025-12-19T07:16:03.197

Link: CVE-2025-66499

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses