CVE-2025-55314: Null Pointer Dereference
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume these states are valid, causing dereference of invalid or released memory. This can lead to memory corruption, application crashes, and potentially allow an attacker to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55314?
The severity of CVE-2025-55314 is currently classified as medium due to the potential risks involved in PDF annotation management.
How do I fix CVE-2025-55314?
To resolve CVE-2025-55314, users should update Foxit PDF and Editor to version 13.2 or 2025.2 or later.
What software is affected by CVE-2025-55314?
CVE-2025-55314 affects Foxit PDF and Editor for Windows and macOS versions prior to 13.2 and 2025 before 2025.2.
What are the potential exploits of CVE-2025-55314?
Exploiting CVE-2025-55314 can lead to incorrect internal state management, resulting in unauthorized annotation access or manipulation.
When was CVE-2025-55314 disclosed?
CVE-2025-55314 was disclosed prior to the release of the fixed versions 13.2 and 2025.2.