Tracker / CVE-2026-57237
CVE-2026-57237
High 7.8
When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the underlying objects referenced by the program to become invalid. Eventually, it reads an illegal memory address, which leads to the crash of the application.
Affected products and versions
| foxit | pdf_editor · … → 13.2.3.63444 |
|---|---|
| foxit | pdf_editor · … → 13.2.4.24048 |
| foxit | pdf_editor · 14.0.0.33046 → 14.0.3.69295 |
| foxit | pdf_editor · 14.0.0.33046 → 14.0.4.33508 |
| foxit | pdf_editor · 2023.1.0.15510 → 2023.3.0.23028 |
| foxit | pdf_editor · 2023.1.0.15510 → 2023.3.0.63083 |
| foxit | pdf_editor · 2024.1.0.23997 → 2024.4.1.27687 |
| foxit | pdf_editor · 2024.1.0.23997 → 2024.4.1.66479 |
| foxit | pdf_editor · 2025.1.0.27937 → 2025.3.0.35737 |
| foxit | pdf_editor · 2025.1.0.27937 → 2025.3.0.69570 |
| foxit | pdf_editor · 2026.1.0.36452 → 2026.1.1.36485 |
| foxit | pdf_editor · 2026.1.0.36452 → 2026.1.1.70276 |
| foxit | pdf_reader · … → 2026.1.1.36485 |
| foxit | pdf_reader · … → 2026.1.1.70276 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.