Impact
Foxit PDF Editor and Foxit PDF Reader contain a cloud‑like appearance rendering path that expands an internal array without setting an upper bound or performing consistency checks. This defect enables an out‑of‑bounds array read that ultimately crashes the application when a malicious PDF is processed. The vulnerability is classified as CWE‑129 and does not provide a delivery mechanism for arbitrary code execution, limiting its effect to a denial of service.
Affected Systems
The affected products are Foxit PDF Editor and Foxit PDF Reader. The CVE does not specify affected versions, so users should consult Foxit’s security bulletins or verify the installed build number against vendor‑provided advisories.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity flaw, while the EPSS score of <1% suggests that exploitation is currently uncommon. The vulnerability is not listed in the CISA KEV catalog. The attack method is inferred to be the normal PDF opening workflow; an attacker would need to supply a specifically crafted PDF to a victim’s machine. No public exploit code is documented, and the flaw does not offer a direct code‑execution path.
OpenCVE Enrichment