Impact
During the opening and formatting of a page, Foxit PDF Editor or Reader processes JavaScript in a way that creates a reentrancy condition. This leads to an inconsistent internal document status, after which the application attempts to read from invalid memory addresses. The out‑of‑bounds read (CWE‑125) causes the program to crash, resulting in a denial of service for the user or local system.
Affected Systems
Foxit Software Inc.'s Foxit PDF Editor and Foxit PDF Reader products are affected. Affected versions are not specified, so it is unclear which releases are vulnerable; any version could be affected pending official vendor guidance.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity. The EPSS score of <1% and the absence of this vulnerability from the CISA KEV catalogue suggest a low likelihood of current exploitation. Based on the description, it is inferred that an attacker would embed malicious JavaScript into a PDF document and entice a user to open it, triggering the reentrancy and causing the crash. Since the flaw only causes a denial of service and does not provide code execution, the threat is limited to service disruption for the target user.
OpenCVE Enrichment