Description
An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an invalid image buffer pointer is used, resulting in the application crashing.
Published: 2026-07-08
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An abnormal image object causes the Foxit PDF renderer to enter the wrong processing branch. When converting the scan lines, an invalid image buffer pointer is used, leading to an out‑of‑bounds read (CWE‑125). The memory read triggers a crash and the application terminates, producing a denial‑of‑service.

Affected Systems

Foxit PDF Editor and Foxit PDF Reader are affected; all current releases may be vulnerable until an official patch or fix is released, as no specific product versions were listed in the advisory.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity. The EPSS score is below 1 % and the vulnerability is not in the CISA KEV catalog. An attacker would need to supply a specially crafted PDF that contains the abnormal image object. The exact method of delivery is not specified, but it is inferred that local or remote access to the victim’s system is required. The primary impact remains an application crash, not code execution or data theft.

Generated by OpenCVE AI on July 29, 2026 at 14:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Foxit PDF Editor and Foxit PDF Reader to the latest releases that contain the renderer fix.
  • If a patch is not available, configure the system or use a sandboxed or restricted viewer to prevent unattended opening of PDFs.
  • Run the PDF viewer in a least‑privilege environment and restrict image processing capabilities when handling untrusted files.

Generated by OpenCVE AI on July 29, 2026 at 14:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader
Vendors & Products Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader

Wed, 08 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an invalid image buffer pointer is used, resulting in the application crashing.
Title Foxit PDF Editor/Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'}


Subscriptions

Foxitsoftware Foxit Pdf Editor Foxit Reader
cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-07-08T12:43:06.097Z

Reserved: 2026-06-24T03:01:18.718Z

Link: CVE-2026-57253

cve-icon Vulnrichment

Updated: 2026-07-08T12:43:00.336Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:45:02Z

Weaknesses