VYPR
High severity7.8NVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026

CVE-2026-57237

CVE-2026-57237

Description

When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the underlying objects referenced by the program to become invalid. Eventually, it reads an illegal memory address, which leads to the crash of the application.

Affected products

3
  • cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*range: <=13.2.4.24048
    • (no CPE)
  • cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*
    Range: <=2026.1.1.36485

Patches

Vulnerability mechanics

References

1

News mentions

1