CVE-2025-55313 Details
Description
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. They allow potential arbitrary code execution when processing crafted PDF files. The vulnerability stems from insufficient handling of memory allocation failures after assigning an extremely large value to a form field's charLimit property via JavaScript. This can result in memory corruption and may allow an attacker to execute arbitrary code by persuading a user to open a malicious file.
A NULL pointer dereference vulnerability has been identified in Foxit PDF and Foxit PDF Editor for Windows and macOS, affecting versions prior to 13.2 and 2025 prior to 2025.2. This vulnerability allows arbitrary code execution when the applications process specially crafted PDF files. The issue arises from inadequate management of memory allocation failures after an extremely large value is assigned to a form field's charLimit property via JavaScript. This can lead to memory corruption, potentially enabling an attacker to execute arbitrary code by convincing a user to open a malicious PDF file.
Users can update to Foxit PDF Reader 2025.2.1 or Foxit PDF Editor 2025.2.1/14.0.1/13.2.1. For Foxit PDF Editor or Reader for Mac, the same version updates apply. Instructions for updating or downloading the latest versions are available on the Foxit website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.foxit.com/support/security-bulletins.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| foxit pdf editor | >= 2023.1.0.15510, <= 2023.3.0.23028 >= 2024.1.0.23997, <= 2024.4.1.27687 2025.1.0.27937 <= 13.1.7.63027 >= 2023.1.0.55583, <= 2023.3.0.63083 >= 2024.1.0.63682, <= 2024.4.1.66479 2025.1.0.66692 |
CPE
Remediation
| |
| foxit pdf reader | <= 2025.1.0.27937 <= 2025.1.0.66692 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 18, 2025 | Initial Analysis | [email protected] |
| Dec 11, 2025 | New CVE Received | [email protected] |
| Dec 11, 2025 | CVE Modified | CISA-ADP |