Impact
A heap‑based out‑of‑bounds read occurs in Foxit PDF Editor/Reader when handling wide strings inside embedded PDF JavaScript. The flaw arises from inadequate validation of string‑deletion ranges, which can trigger an integer underflow. This leads to a read beyond the bounds of a heap buffer and causes the application to terminate unexpectedly. The vulnerability does not directly allow code execution, but the crash could be leveraged in a broader exploit chain or used as a denial‑of‑service vector.
Affected Systems
The issue affects both Foxit PDF Editor and Foxit PDF Reader from Foxit Software Inc. The CVE does not enumerate specific product revisions, implying that all publicly released versions that parse embedded PDF JavaScript are susceptible.
Risk and Exploitability
The CVSS score of 6.1 reflects a moderate severity, while the EPSS score of less than 1% indicates a low likelihood of active exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. It is likely to be exploited by attackers who craft malicious PDF files with malicious JavaScript, hoping to crash the target application. Because the flaw is limited to a buffer read and does not expose a clear control‑flow hijack, the overall risk is moderate, but the impact on user experience and potential for cascading failures warrants attention.
OpenCVE Enrichment