CVE-2026-57237

EUVD-2026-42196
When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the underlying objects referenced by the program to become invalid. Eventually, it reads an illegal memory address, which leads to the crash of the application.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 1.9%
Affected Products (NVD)
VendorProductVersion
foxitpdf_editor
𝑥
≤ 13.2.4.24048
foxitpdf_editor
14.0.0.33046 ≤
𝑥
≤ 14.0.4.33508
foxitpdf_editor
2023.1.0.15510 ≤
𝑥
≤ 2023.3.0.23028
foxitpdf_editor
2024.1.0.23997 ≤
𝑥
≤ 2024.4.1.27687
foxitpdf_editor
2025.1.0.27937 ≤
𝑥
≤ 2025.3.0.35737
foxitpdf_editor
2026.1.0.36452 ≤
𝑥
≤ 2026.1.1.36485
foxitpdf_reader
𝑥
≤ 2026.1.1.36485
foxitpdf_editor
𝑥
≤ 13.2.3.63444
foxitpdf_editor
14.0.0.33046 ≤
𝑥
≤ 14.0.3.69295
foxitpdf_editor
2023.1.0.15510 ≤
𝑥
≤ 2023.3.0.63083
foxitpdf_editor
2024.1.0.23997 ≤
𝑥
≤ 2024.4.1.66479
foxitpdf_editor
2025.1.0.27937 ≤
𝑥
≤ 2025.3.0.69570
foxitpdf_editor
2026.1.0.36452 ≤
𝑥
≤ 2026.1.1.70276
foxitpdf_reader
𝑥
≤ 2026.1.1.70276
𝑥
= Vulnerable software versions