VYPR
Unrated severityNVD Advisory· Published Dec 19, 2025· Updated Dec 19, 2025

Foxit PDF Reader PDF Parsing Heap-Based Buffer Overflow Remote Code Execution Vulnerability

CVE-2025-66499

Description

A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data. An integer overflow in the calculation of the image buffer size may occur, potentially allowing a remote attacker to execute arbitrary code.

Affected products

3
  • Foxit/Pdf Readerllm-fuzzy
  • Foxit Software Inc./Foxit PDF Editorv5
    Range: Versions 2025.2.1 and earlier
  • Foxit Software Inc./Foxit PDF Readerv5
    Range: Versions 2025.2.1 and earlier

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.