📦

pdf_editor

Vendor: foxit

Actively Exploited 0 CISA KEV List
PoC / Exploits 6 Code Available
Total RCEs 202 Remote Access
Total CVEs 334 Total Indexed
Avg. EPSS 1.06% Exploit Prob.
Latest CVE CVE-2026-57260 Jul 08

Security Vulnerability Index

Page 4 / 34
7.8 CVSS

Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form field hierarchies, leading to invalid memory writes and program crashes during internal data structure construction.

EPSS: 0.17%
7.8 CVSS

Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes.

EPSS: 0.17%
5.5 CVSS

A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution.

EPSS: 0.11%
5.5 CVSS

Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service.

EPSS: 0.10%
5.5 CVSS

Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "std::invalid_argument" exception, ultimately causing the program to terminate.

EPSS: 0.10%
7.3 CVSS
CVE-2026-3780
Exploit Found

The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legitimate system files, resulting in local privilege escalation.

EPSS: 0.12%
7.8 CVSS

The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary code execution.

EPSS: 0.31%
6.2 CVSS

The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pages and annotations are crafted that reference each other in a loop, passing the document to APIs (e.g., SOAP) that perform deep traversal can cause uncontrolled recursion, stack exhaustion, and application crashes.

EPSS: 0.10%
5.5 CVSS

The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and page state. When a script modifies the zoom property and then triggers a page change, the original view object may be destroyed while stale pointers are still kept and later dereferenced, which under crafted JavaScript and document structures can lead to a use-after-free condition and potentially allow arbitrary code execution.

EPSS: 0.12%
5.5 CVSS

The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp annotation missing its AP entry, the code continues to dereference the associated object without a prior null or validity check, which allows a crafted document to trigger a null pointer dereference and crash the application, resulting in denial of service.

EPSS: 0.10%