Vulnerability Database

317,105

Total vulnerabilities in the database

CVE-2025-66498

A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing U3D data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.

  • Published: Dec 19, 2025
  • Updated: Dec 20, 2025
  • CVE: CVE-2025-66498
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 5.3
  • AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Software From Fixed in
foxit / pdf_editor - 13.2.1.23955.x
foxit / pdf_editor 14.0.0.33046 14.0.1.33197.x
foxit / pdf_editor 2023.1.0.15510 2023.3.0.23028.x
foxit / pdf_editor 2024.1.0.23997 2024.4.1.27687.x
foxit / pdf_editor 2025.1.0.27937 2025.2.1.33197.x
foxit / pdf_reader - 2025.2.1.33197.x