漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Use after free of view cache in Foxit PDF Editor/Reader
Vulnerability Description
The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and page state. When a script modifies the zoom property and then triggers a page change, the original view object may be destroyed while stale pointers are still kept and later dereferenced, which under crafted JavaScript and document structures can lead to a use-after-free condition and potentially allow arbitrary code execution.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Vulnerability Type
释放后使用
Vulnerability Title
Foxit PDF Reader和Foxit PDF Editor 安全漏洞
Vulnerability Description
Foxit PDF Reader和Foxit PDF Editor都是中国福昕(Foxit)公司的产品。Foxit PDF Reader是一款PDF阅读器。Foxit PDF Editor是一款PDF编辑器。 Foxit PDF Reader和Foxit PDF Editor存在安全漏洞,该漏洞源于JavaScript更改文档缩放和页面状态后未正确验证内部视图缓存指针的生命周期和有效性,可能导致释放后重用,并可能允许任意代码执行。
CVSS Information
N/A
Vulnerability Type
N/A