PatchSiren

Foxit Software Inc. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57260

An application crashed while parsing a PDF file containing an abnormal Unity 3D object. The application incorrectly resolved a portion of the object as a pointer and used it as a valid address. This vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. The affected product or component is not explicitly stated, but it is likely related to applications that parse PDF files containing Un [truncated]

MEDIUM Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57259

A medium-severity vulnerability, CVE-2026-57259, has been identified in a PDF parser. The input file does not need to be in a structurally valid PDF format. Malicious documents can construct external entities that point to local paths, allowing access to local files within the user's permission range. This vulnerability requires user interaction and has a limited attack surface. Users of PDF parsing softw [truncated]

MEDIUM Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57258

CVE-2026-57258 is a MEDIUM severity vulnerability in the PRC file header parsing logic, which leads to out-of-bounds reads and application crashes with a CVSS score of 6.1. The vulnerability affects Foxit software, and users should review their installations for potential exposure. The CVE record and NVD entry provide more information about the vulnerability. The debrief is based on the supplied source co [truncated]

MEDIUM Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57257

A vulnerability was found in an unspecified product, where during the PRC parsing stage, there is a lack of boundary verification for the PRC entity index. This leads to an out-of-bounds read of the entity array, causing the application to crash. The CVSS score for this vulnerability is 6.1, indicating a medium severity. Organizations and users of the affected product should be aware of this vulnerability [truncated]

HIGH Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57256

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-08T09:16:33.770Z and has not been modified since then. This CVE describes a vulnerability in Foxit software where executing JavaScript in PDFs can lead to abnormal operations on list box fields, causing an application crash due to illegal pointer reads. Users should review and apply security updates [truncated]

MEDIUM Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57255

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-08T09:16:33.647Z and has not been modified since then. This CVE concerns a vulnerability in applications that process PDFs, particularly those handling color spaces. The vulnerability could lead to application crashes due to malformed PDFs. Users of such applications should verify their software's h [truncated]

HIGH Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57254

A vulnerability in the PDF parsing functionality of an unspecified application could allow an attacker to cause a crash. The issue arises from the application's failure to perform proper type checking on an abnormal annotation within the PDF that is referenced by other objects. This issue is triggered by a specific type of malformed PDF content, which could lead to denial-of-service attacks. Users of appl [truncated]

MEDIUM Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57253

An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an invalid image buffer pointer is used, resulting in the application crashing. This issue has a CVSS score of 6.1 and a severity of MEDIUM. The vulnerability occurs when an abnormal image object causes the renderer to enter the wrong processing branch. During scan line conversion, an invalid [truncated]

HIGH Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57252

A high-severity vulnerability, CVE-2026-57252, was found in Foxit's PDF application. The issue causes the application to crash when a PDF file is opened and pages are deleted with attachment annotations. This vulnerability can potentially be used for malicious purposes, and users of Foxit's PDF application should be aware of this vulnerability and take necessary precautions. The vulnerability occurs due t [truncated]

HIGH Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57251

A HIGH severity vulnerability, CVE-2026-57251, was found in an application that opens PDFs. The issue arises from the lack of proper upper limit setting and consistency checks during the construction process, which has a cloud-like appearance. This oversight exposes out-of-bounds access to the underlying array, ultimately causing the application to crash. The vulnerability has a HIGH CVSS score of 7.8, in [truncated]

HIGH Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57250

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-08T09:16:33.070Z and has not been modified since then. This high-severity vulnerability affects Foxit PDF application, potentially leading to application crashes when processing malicious PDFs with JavaScript. The vulnerability is particularly concerning due to its high CVSS score of 7.8. Users shou [truncated]

HIGH Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57249

A HIGH severity vulnerability, CVE-2026-57249, was found in an unknown vendor's application. The vulnerability causes the application to crash when opening a PDF file due to invalid object access during a re-entry process. This occurs after a script resets the annotation status and triggers a reset form event. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. Users of the affec [truncated]

HIGH Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57248

A HIGH severity vulnerability, CVE-2026-57248, was found in an unspecified application. The vulnerability occurs when the application opens a PDF file and JavaScript writes annotation attributes, lacking sufficient object type and argument checks. This causes damage to the internal structure of the annotations, leading to an application crash during subsequent release. The affected product or component is [truncated]

HIGH Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57247

The application re-enters the document structure via field processing and deletes the current page, and then continues using the field objects obtained before deletion, triggering an illegal read and crashing. This CVE was published on 2026-07-08T09:16:32.737Z and has not been modified since then. The vulnerability affects Foxit software users, who should review their systems for potential vulnerabilities [truncated]

HIGH Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57246

A lack of argument validation in JavaScript signature verification can cause the application to crash when dealing with abnormally constructed objects. This HIGH severity vulnerability, with a CVSS score of 7.8, affects the application when dealing with abnormally constructed objects. The vulnerability is caused by a lack of argument validation in JavaScript signature verification. The signature plugin do [truncated]

HIGH Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57245

A high-severity vulnerability exists in an application that fails to validate abnormal annotation relationships and field combinations in PDFs. This results in an invalid pointer write, causing the application to crash. The vulnerability has a CVSS score of 7.8 and is considered HIGH. The affected product or component is a PDF handling application. The vulnerability class is related to CWE-416. The likely [truncated]

HIGH Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57244

A high-severity vulnerability, CVE-2026-57244, has been identified in an unspecified product by an unknown vendor. The issue arises from a lack of re-entry protection and object lifecycle verification in the synchronization process after JavaScript resets a form. This results in a control pointer failure during traversal, leading to a crash. The vulnerability has a CVSS score of 7.8 and is classified as H [truncated]

MEDIUM Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57243

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-08T09:16:32.267Z and has not been modified since then. This vulnerability, CVE-2026-57243, is classified as a medium severity issue with a CVSS score of 6.1. It involves a JavaScript reentrancy during page opening and form formatting, leading to an inconsistent document status. Subsequently, the app [truncated]

HIGH Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57242

The CVE-2026-57242 vulnerability is related to a PDF handling issue in applications using Foxit PDF components. The application opens a PDF and allows JavaScript to modify forms. However, related page objects lack complete lifecycle management and null value validation. When the page state changes, the application continuously dereferences invalid objects, leading to a crash. This vulnerability has a CVSS [truncated]

MEDIUM Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57241

CVE-2026-57241 is a medium-severity vulnerability that causes an application to crash due to out-of-bounds access when processing PDFs with JavaScript. The application opens a PDF and JavaScript performs operations on the page and document, causing page-related objects to lose synchronization. However, the renderer still trusts the outdated page count, leading to an application crash.

HIGH Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57240

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-08T09:16:31.927Z and has not been modified since then. This vulnerability affects applications that open and process PDF files, particularly those using JavaScript for dynamic content. The vulnerability class involves invalid pointer references caused by JavaScript deleting PDF fields while the appl [truncated]

HIGH Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57239

A high-severity vulnerability, CVE-2026-57239, has been identified in a product from an unknown vendor. The vulnerability has a CVSS score of 8.2 and allows low-privilege users to potentially elevate their privileges to NT AUTHORITYSYSTEM due to the direct execution of user-controllable executable files by high-privilege processes. This vulnerability arises from the direct execution of user-controllable e [truncated]

HIGH Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57238

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-08T09:16:31.693Z and has not been modified since then. This high-severity vulnerability affects the Foxit PDF application, allowing JavaScript to delete a form field object and subsequently crash the application. Users and administrators should be aware of the potential denial-of-service impact and [truncated]

HIGH Foxit Software Inc. CVE published 2026-07-08

CVE-2026-57237

A high-severity vulnerability, CVE-2026-57237, was found in an application that causes a crash when opening a PDF and JavaScript modifies form field properties. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. The affected application fails to handle JavaScript modifications to form field properties in PDFs, leading to an invalid state of underlying objects and eventually causing the a [truncated]

HIGH Foxit Software Inc. CVE published 2026-07-08

CVE-2026-13129

A high-severity vulnerability, CVE-2026-13129, was found in Foxit PDF software. When opening a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form object when accessing the field property path. Eventually, the application crashes due to reading an invalid pointer. The vulnerability has a CVSS score of 7.8, indicating a high severity [truncated]

HIGH Foxit Software Inc. CVE published 2026-07-08

CVE-2026-13127

A high-severity vulnerability, CVE-2026-13127, has been identified in an application that opens PDF files. When a PDF file is opened, JavaScript rewrites the document to modify the page structure, invalidating page objects. However, thumbnails continue to use these invalid page objects, ultimately causing the application to crash. The affected product or component is likely a PDF processing application. T [truncated]

HIGH Foxit Software Inc. CVE published 2026-07-08

CVE-2026-13126

The CVE record for CVE-2026-13126 was published on 2026-07-08T09:16:29.307Z and has not been modified since then. This vulnerability affects Foxit PDF software, potentially allowing attackers to exploit the embedded JavaScript in PDFs, leading to program crashes. The vulnerability has a high CVSS score of 7.8, indicating high severity. Users of Foxit PDF software should review their systems for potential [truncated]

HIGH Foxit Software Inc. CVE published 2026-06-15

CVE-2026-12057

A HIGH severity vulnerability was discovered in an Unknown Vendor product, tracked as CVE-2026-12057 with a CVSS score of 8.6. The vulnerability occurs when the application executes a JavaScript script embedded in a PDF within a sandbox, failing to intercept some dangerous interfaces. This allows remote scripts to be loaded, resulting in arbitrary code execution.