CVE-2025-66499

A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data. An integer overflow in the calculation of the image buffer size may occur, potentially allowing a remote attacker to execute arbitrary code.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
FoxitCNA
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
VendorProductVersion
foxitpdf_editor
𝑥
≤ 13.2.1.23955
foxitpdf_editor
14.0.0.33046 ≤
𝑥
≤ 14.0.1.33197
foxitpdf_editor
2023.1.0.15510 ≤
𝑥
≤ 2023.3.0.23028
foxitpdf_editor
2024.1.0.23997 ≤
𝑥
≤ 2024.4.1.27687
foxitpdf_editor
2025.1.0.27937 ≤
𝑥
≤ 2025.2.1.33197
foxitpdf_reader
𝑥
≤ 2025.2.1.33197
foxitpdf_editor
𝑥
≤ 13.2.1.63315
foxitpdf_editor
14.0.0.33046 ≤
𝑥
≤ 14.0.1.69005
foxitpdf_editor
2023.1.0.15510 ≤
𝑥
≤ 2023.3.0.63083
foxitpdf_editor
2024.1.0.23997 ≤
𝑥
≤ 2024.4.1.66479
foxitpdf_editor
2025.1.0.27937 ≤
𝑥
≤ 2025.2.1.69005
foxitpdf_reader
𝑥
≤ 2025.2.1.69005
𝑥
= Vulnerable software versions