Impact
An abnormal image object causes the Foxit PDF renderer to enter the wrong processing branch. When converting the scan lines, an invalid image buffer pointer is used, leading to an out‑of‑bounds read (CWE‑125). The memory read triggers a crash and the application terminates, producing a denial‑of‑service.
Affected Systems
Foxit PDF Editor and Foxit PDF Reader are affected; all current releases may be vulnerable until an official patch or fix is released, as no specific product versions were listed in the advisory.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS score is below 1 % and the vulnerability is not in the CISA KEV catalog. An attacker would need to supply a specially crafted PDF that contains the abnormal image object. The exact method of delivery is not specified, but it is inferred that local or remote access to the victim’s system is required. The primary impact remains an application crash, not code execution or data theft.
OpenCVE Enrichment