CVE-2025-66499
published 2025-12-19CVE-2025-66499: A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data. An integer overflow in…
PriorityP342high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.26%
17.2th percentile
A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data. An integer overflow in the calculation of the image buffer size may occur, potentially allowing a remote attacker to execute arbitrary code.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxit | pdf_editor | <= 13.2.1.23955 | — |
| foxit | pdf_editor | <= 13.2.1.63315 | — |
| foxit | pdf_editor | 14.0.0.33046 – 14.0.1.33197 | — |
| foxit | pdf_editor | 14.0.0.33046 – 14.0.1.69005 | — |
| foxit | pdf_editor | 2023.1.0.15510 – 2023.3.0.23028 | — |
| foxit | pdf_editor | 2023.1.0.15510 – 2023.3.0.63083 | — |
| foxit | pdf_editor | 2024.1.0.23997 – 2024.4.1.27687 | — |
| foxit | pdf_editor | 2024.1.0.23997 – 2024.4.1.66479 | — |
| foxit | pdf_editor | 2025.1.0.27937 – 2025.2.1.33197 | — |
| foxit | pdf_editor | 2025.1.0.27937 – 2025.2.1.69005 | — |
| foxit | pdf_reader | <= 2025.2.1.33197 | — |
| foxit | pdf_reader | <= 2025.2.1.69005 | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_reader | — | — |
| foxit_software_inc | foxit_pdf_reader | — | — |
| foxit_software_inc | foxit_pdf_reader | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-66495 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2025-66495 [HIGH] CVE-2025-66495 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66495 :
Foxit PDF Reader vulnerability analysis and mitigation
A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows and MacOS. When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be accessed or dereferenced, potentially allowing a remote attacker to execute arbitrary code.
Source : NVD
## 7.8
Score
Published December 19, 2025
Severity HIGH
CNA Score 7.8
Affected Technologies
Foxit PDF Reader
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 18.6
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:foxit:pdf_read
Wiz
CVE-2025-55309 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.7
CVE-2025-55309 [MEDIUM] CVE-2025-55309 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-55309 :
Foxit PDF Reader vulnerability analysis and mitigation
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can contain JavaScript that attaches an OnBlur action on a form field that destroys an annotation. During user right-click interaction, the program's internal focus change handling prematurely releases the annotation object, resulting in a use-after-free vulnerability that may cause memory corruption or application crashes.
Source : NVD
## 6.7
Score
Published December 11, 2025
Severity MEDIUM
CNA Score 6.7
Affected Technologies
Foxit PDF Reader
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.
Wiz
CVE-2025-59803 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2025-59803 [MEDIUM] CVE-2025-59803 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-59803 :
Foxit PDF Reader vulnerability analysis and mitigation
Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker can embed triggers (e.g., JavaScript) in a PDF document that execute during the signing process. When a signer reviews the document, the content appears normal. However, once the signature is applied, the triggers modify content on other pages or optional content layers without explicit warning. This can cause the signed PDF to differ from what the signer saw, undermining the trustworthiness of the digital signature. The fixed versions are 2025.2.1, 14.0.1, and 13.2.1.
Source : NVD
## 5.3
Score
Published December 11, 2025
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Foxit PDF Reader
Has Public Exploit N
Wiz
CVE-2025-13941 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-13941 [HIGH] CVE-2025-13941 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-13941 :
Foxit PDF Reader vulnerability analysis and mitigation
A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installation, incorrect file system permissions are assigned to resources used by the update service. A local attacker with low privileges could modify or replace these resources, which are later executed by the service, resulting in execution of arbitrary code with SYSTEM privileges.
Source : NVD
## 8.8
Score
Published December 19, 2025
Severity HIGH
CNA Score 8.8
Affected Technologies
Foxit PDF Reader
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.5
Exploitation Probability (EPSS) N/A
Affected pa
Wiz
CVE-2025-55314 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2025-55314 [HIGH] CVE-2025-55314 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-55314 :
Foxit PDF Reader vulnerability analysis and mitigation
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume these states are valid, causing dereference of invalid or released memory. This can lead to memory corruption, application crashes, and potentially allow an attacker to execute arbitrary code.
Source : NVD
## 7.8
Score
Published December 11, 2025
Severity HIGH
CNA Score 7.8
Affected Technologies
Foxit PDF Reader
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentil
Wiz
CVE-2025-66494 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2025-66494 [HIGH] CVE-2025-66494 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66494 :
Foxit PDF Reader vulnerability analysis and mitigation
A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows. A PDF object managed by multiple parent objects could be freed while still being referenced, potentially allowing a remote attacker to execute arbitrary code.
Source : NVD
## 7.8
Score
Published December 19, 2025
Severity HIGH
CNA Score 7.8
Affected Technologies
Foxit PDF Reader
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 18.6
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:foxit:pdf_reader
Sources
Linux Severity HIGH Has Fix Added at: Dec 24, 20
Wiz
CVE-2025-66496 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2025-66496 [HIGH] CVE-2025-66496 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66496 :
Foxit PDF Reader vulnerability analysis and mitigation
A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.
Source : NVD
## 7.8
Score
Published December 19, 2025
Severity HIGH
CNA Score 5.3
Affected Technologies
Foxit PDF Reader
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:foxit:pdf_reader
Sources
Linux Severity HIGH Has Fix Added at:
Wiz
CVE-2025-55308 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.7
CVE-2025-55308 [MEDIUM] CVE-2025-55308 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-55308 :
Foxit PDF Reader vulnerability analysis and mitigation
An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. A crafted PDF containing JavaScript that calls closeDoc() while internal objects are still in use can cause premature release of these objects. This use-after-free vulnerability may lead to memory corruption, potentially resulting in information disclosure when the PDF is opened.
Source : NVD
## 6.7
Score
Published December 11, 2025
Severity MEDIUM
CNA Score 6.7
Affected Technologies
Foxit PDF Reader
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.5
Exploitation Probability (EPSS) N/A
Affected packages and librari
Wiz
CVE-2025-55307 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2025-55307 [LOW] CVE-2025-55307 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-55307 :
Foxit PDF Reader vulnerability analysis and mitigation
An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. Opening a malicious PDF containing a crafted JavaScript call to search.query() with a crafted cDIPath parameter (e.g., "/") may cause an out-of-bounds read in internal path-parsing logic, potentially leading to information disclosure or memory corruption.
Source : NVD
## 3.3
Score
Published December 11, 2025
Severity LOW
CNA Score 3.3
Affected Technologies
Foxit PDF Reader
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:foxit:pdf_read
Wiz
CVE-2025-66499 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2025-66499 [HIGH] CVE-2025-66499 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66499 :
Foxit PDF Reader vulnerability analysis and mitigation
A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data. An integer overflow in the calculation of the image buffer size may occur, potentially allowing a remote attacker to execute arbitrary code.
Source : NVD
## 7.8
Score
Published December 19, 2025
Severity HIGH
CNA Score 7.8
Affected Technologies
Foxit PDF Reader
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.1
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:foxit:pdf_reader
Sources
Linux Severity HIGH Has Fix Added at: Dec 24, 2025
Windows S
Wiz
CVE-2025-55313 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2025-55313 [HIGH] CVE-2025-55313 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-55313 :
Foxit PDF Reader vulnerability analysis and mitigation
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. They allow potential arbitrary code execution when processing crafted PDF files. The vulnerability stems from insufficient handling of memory allocation failures after assigning an extremely large value to a form field's charLimit property via JavaScript. This can result in memory corruption and may allow an attacker to execute arbitrary code by persuading a user to open a malicious file.
Source : NVD
## 7.8
Score
Published December 11, 2025
Severity HIGH
CNA Score 7.8
Affected Technologies
Foxit PDF Reader
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date
Wiz
CVE-2026-3774 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-3774 [MEDIUM] CVE-2026-3774 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3774 :
Foxit PDF Reader vulnerability analysis and mitigation
The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, annotations, or optional content groups (OCGs) immediately before or after redaction, encryption, or printing. These script‑driven updates are not fully covered by the existing redaction, encryption, and printing logic, which, under specific document structures and user workflows, may cause a small amount of sensitive content to remain unremoved or unencrypted as expected, or result in printed output that slightly differs from what was reviewed on screen.
Source : NVD
## 4.7
Score
Published April 1, 2026
Severity MEDIUM
CNA Score 4.7
Affected Technologies
Foxit PDF Reader
Has Public Exploi
Wiz
CVE-2025-55310 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.3
CVE-2025-55310 [HIGH] CVE-2025-55310 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-55310 :
Foxit PDF Reader vulnerability analysis and mitigation
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. An attacker able to alter or replace the static HTML files used by the StartPage feature can cause the application to load malicious or compromised content upon startup. This may result in information disclosure, unauthorized data access, or other security impacts.
Source : NVD
## 7.3
Score
Published December 11, 2025
Severity HIGH
CNA Score 7.3
Affected Technologies
Foxit PDF Reader
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe
Wiz
CVE-2025-59802 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-59802 [HIGH] CVE-2025-59802 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-59802 :
Foxit PDF Reader vulnerability analysis and mitigation
Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via OCG. When Optional Content Groups (OCG) are supported, the state property of an OCG is runtime-only and not included in the digital signature computation buffer. An attacker can leverage JavaScript or PDF triggers to dynamically change the visibility of OCG content after signing (Post-Sign), allowing the visual content of a signed PDF to be modified without invalidating the signature. This may result in a mismatch between the signed content and what the signer or verifier sees, undermining the trustworthiness of the digital signature. The fixed versions are 2025.2.1, 14.0.1, and 13.2.1.
Source : NVD
## 7.5
Score
Published December 11, 2
Wiz
CVE-2025-55311 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-55311 [MEDIUM] CVE-2025-55311 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-55311 :
Foxit PDF Reader vulnerability analysis and mitigation
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can use JavaScript to alter annotation content and subsequently clear the file's modification status via JavaScript interfaces. This circumvents digital signature verification by hiding document modifications, allowing an attacker to mislead users about the document's integrity and compromise the trustworthiness of signed PDFs.
Source : NVD
## 6.5
Score
Published December 11, 2025
Severity MEDIUM
CNA Score 6.5
Affected Technologies
Foxit PDF Reader
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS
Wiz
CVE-2025-66498 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2025-66498 [HIGH] CVE-2025-66498 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66498 :
Foxit PDF Reader vulnerability analysis and mitigation
A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing U3D data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.
Source : NVD
## 7.8
Score
Published December 19, 2025
Severity HIGH
CNA Score 5.3
Affected Technologies
Foxit PDF Reader
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:foxit:pdf_reader
Sources
Linux Severity HIGH Has Fix Added at:
Wiz
CVE-2025-66493 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2025-66493 [HIGH] CVE-2025-66493 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66493 :
Foxit PDF Reader vulnerability analysis and mitigation
A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,14.0.1 and 13.2.1
on Windows
. When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be accessed or dereferenced, potentially allowing a remote attacker to execute arbitrary code.
Source : NVD
## 7.8
Score
Published December 19, 2025
Severity HIGH
CNA Score 7.8
Affected Technologies
Foxit PDF Reader
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 18.6
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:foxi
Wiz
CVE-2025-66497 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2025-66497 [HIGH] CVE-2025-66497 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66497 :
Foxit PDF Reader vulnerability analysis and mitigation
A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.
Source : NVD
## 7.8
Score
Published December 19, 2025
Severity HIGH
CNA Score 5.3
Affected Technologies
Foxit PDF Reader
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:foxit:pdf_reader
Sources
Linux Severity HIGH Has Fix Added at:
Wiz
CVE-2025-55312 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2025-55312 [HIGH] CVE-2025-55312 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-55312 :
Foxit PDF Reader vulnerability analysis and mitigation
An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume these states are valid, causing dereference of invalid or released memory. This can lead to memory corruption, application crashes, and potentially allow an attacker to execute arbitrary code.
Source : NVD
## 7.8
Score
Published December 11, 2025
Severity HIGH
CNA Score 7.8
Affected Technologies
Foxit PDF Reader
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1
2025-12-19
Published