CVE-2025-32451
A memory corruption vulnerability exists in Foxit Reader 2025.1.0.27937 due to the use of an uninitialized pointer. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS probability
- 0.58%
- CWE
- CWE-824
- Published
- 2025-08-13
- Last modified
- 2026-03-13
Affected products
- Foxit Foxit Reader
Weakness type
Related vulnerabilities
- CVE-2026-88054 — Tesseract: Denial of service via empty-stack dereference in Plumbing/Series at model load
- CVE-2026-67281 — Unauthenticated file read in Mikrotik RouterOS
- CVE-2026-54920 — OpenEXR: Integer overflow and uninitialized pointer cause invalid delete in OpenEXRUtil image resize
- CVE-2026-47908 — Dreamweaver Desktop | Access of Uninitialized Pointer (CWE-824)
- CVE-2026-47320 — Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source...
- CVE-2026-42959 — Crash during DNSSEC validation of malicious content
- CVE-2026-39458 — BIG-IP DNS Cache vulnerability
- CVE-2026-44411 — A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5). The...