cbcvebase.
CVE-2025-66499
published 2025-12-19

CVE-2025-66499: A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data. An integer overflow in…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data. An integer overflow in the calculation of the image buffer size may occur, potentially allowing a remote attacker to execute arbitrary code.

Affected

18 ranges
VendorProductVersion rangeFixed in
foxitpdf_editor<= 13.2.1.23955
foxitpdf_editor<= 13.2.1.63315
foxitpdf_editor14.0.0.33046 – 14.0.1.33197
foxitpdf_editor14.0.0.33046 – 14.0.1.69005
foxitpdf_editor2023.1.0.15510 – 2023.3.0.23028
foxitpdf_editor2023.1.0.15510 – 2023.3.0.63083
foxitpdf_editor2024.1.0.23997 – 2024.4.1.27687
foxitpdf_editor2024.1.0.23997 – 2024.4.1.66479
foxitpdf_editor2025.1.0.27937 – 2025.2.1.33197
foxitpdf_editor2025.1.0.27937 – 2025.2.1.69005
foxitpdf_reader<= 2025.2.1.33197
foxitpdf_reader<= 2025.2.1.69005
foxit_software_incfoxit_pdf_editor
foxit_software_incfoxit_pdf_editor
foxit_software_incfoxit_pdf_editor
foxit_software_incfoxit_pdf_reader
foxit_software_incfoxit_pdf_reader
foxit_software_incfoxit_pdf_reader