CVE-2026-3779: Foxit PDF Editor/Reader List Box Calculate Array Use-After-Free Vulnerability
The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3779?
CVE-2026-3779 has been classified with high severity due to its potential impact on application stability and security.
How do I fix CVE-2026-3779?
To fix CVE-2026-3779, update your Foxit PDF Editor or Reader to the latest version that addresses this vulnerability.
Which software is affected by CVE-2026-3779?
CVE-2026-3779 affects Foxit PDF Editor and Foxit Reader.
What type of vulnerability is CVE-2026-3779?
CVE-2026-3779 is a use-after-free vulnerability related to the handling of list box calculate arrays.
Can CVE-2026-3779 lead to code execution?
Yes, CVE-2026-3779 can potentially allow an attacker to execute arbitrary code through crafted documents.