← Volver a CVEs
CVE-2025-66499
HIGH7.8
Descripcion
A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data. An integer overflow in the calculation of the image buffer size may occur, potentially allowing a remote attacker to execute arbitrary code.
Detalles CVE
Puntuacion CVSS v3.17.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vector de ataqueLOCAL
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioREQUIRED
Publicado12/19/2025
Ultima modificacion12/23/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
apple:macosfoxit:pdf_editorfoxit:pdf_readermicrosoft:windows
Debilidades (CWE)
CWE-190
Referencias
https://www.foxit.com/support/security-bulletins.html(14984358-7092-470d-8f34-ade47a7658a2)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.