Impact
The vulnerability is a classic buffer overflow (CWE-120) that arises when the signature verification plugin copies an abnormally constructed string without validating its length or content during JavaScript execution. This flaw can be triggered while a user opens a PDF that contains a malformed object; the unchecked copy operation causes the Foxit PDF Editor or Reader to crash, denying service or allowing an attacker to influence the end‑user's workspace.
Affected Systems
Foxit PDF Editor and Foxit PDF Reader from Foxit Software Inc. are affected. Because the CVE does not list specific affected versions, any installation of these products may be vulnerable until a vendor update is released.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score of less than 1% indicates that exploitation is unlikely at present. The vulnerability is not indexed in the CISA KEV catalog. Based on the description, it is inferred that the flaw can be triggered by a PDF file with crafted malformed objects, which an attacker could deliver via email, a compromised website, or another file‑transfer vector. The available information does not imply remote code execution; the primary impact is a denial of service through application crash.
OpenCVE Enrichment