Critical severity9.8NVD Advisory· Published Feb 11, 2022· Updated Jun 17, 2026
CVE-2022-24954
CVE-2022-24954
Description
Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpan="-2"' and 'draw colSpan="1"' substrings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*range: <=10.1.6.37749
- (no CPE)range: <11.2.1
cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*range: <=11.1.0.52543
- (no CPE)
- (no CPE)range: <11.2.1
Patches
Vulnerability mechanics
References
2- www.foxit.com/support/security-bulletins.htmlnvdPatchVendor Advisory
- twitter.com/l33d0hyun/status/1487047927415459851nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.