Impact
A PDF containing JavaScript that deletes a form field object after the document is opened triggers a use‑after‑free condition in Foxit PDF Editor and Foxit PDF Reader. When the application later attempts to use this invalid object, it crashes416 and results in a denial‑of‑service scenario by causing the reader to terminate unexpectedly.
Affected Systems
The vulnerability affects Foxit PDF Editor and Foxit PDF Reader from Foxit Software Inc. No specific version range is provided in all released versions from the time of the advisory should be verified for the presence of the flaw.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity of the issue. The EPSS score of <1% shows a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, implying no widespread exploits are currently known. The likely attack vector is that an attacker supplies a malicious PDF that includes the offending JavaScript; when processed by the application the program to crash, interrupting service for the user.
OpenCVE Enrichment