Description
When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and this operation is repeated after the form is reset. During this process, the application failed to adequately verify the validity of the form objects and their internal dictionary pointers, resulting in accessing internal members of invalid or improperly initialized fields. This led to an illegal pointer read, ultimately causing the application to crash.
Published: 2026-07-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Foxit PDF Editor and Foxit PDF Reader are vulnerable to a use‑after‑free flaw in list‑box field handling that is triggered when a PDF containing JavaScript is opened. The flaw, classified as CWE‑416: Use After Free, causes the application to reference an invalid pointer during repeated list‑box operations after a form reset, resulting in an illegal pointer read and an application crash. The impact is limited to denial of service as the crash terminates the process, with no evidence that it allows arbitrary code execution. The vulnerability is not a local privilege escalation or a remote code execution scenario.

Affected Systems

Both Foxit PDF Editor and Foxit PDF Reader are affected. The CVE does not provide specific version numbers, so all releases of these products should be treated as potentially vulnerable until a patch that contains the fix is applied. Updates for both editor and reader are available on the Foxit security bulletin page.

Risk and Exploitability

The CVSS base score of 7.8 indicates a significant service impact. The EPSS score of < 1% implies a low probability of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires a victim to open a malicious PDF that contains JavaScript, so social engineering or phishing is typically necessary. When exploitation occurs, the process crashes, potentially disrupting the user or any services that depend on the PDF application. Real‑world risk remains low but non‑zero, particularly in environments where users frequently open PDFs from untrusted sources.

Generated by OpenCVE AI on July 29, 2026 at 14:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Foxit PDF Editor and Fox CVE‑2026‑57256 fix.
  • Configure the PDF viewer to disable or restrict JavaScript execution in PDFs to prevent the execution of malicious scripts.
  • Run the PDF viewer in a sandboxed or restricted environment so that crashes cannot affect the host system or other applications.

Generated by OpenCVE AI on July 29, 2026 at 14:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader
Vendors & Products Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader

Wed, 08 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and this operation is repeated after the form is reset. During this process, the application failed to adequately verify the validity of the form objects and their internal dictionary pointers, resulting in accessing internal members of invalid or improperly initialized fields. This led to an illegal pointer read, ultimately causing the application to crash.
Title Foxit Editor/Reader List Box Format Use-After-Free Vulnerability
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Foxitsoftware Foxit Pdf Editor Foxit Reader
cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-07-09T17:37:54.106Z

Reserved: 2026-06-24T03:01:18.718Z

Link: CVE-2026-57256

cve-icon Vulnrichment

Updated: 2026-07-09T17:37:54.106Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:45:02Z

Weaknesses