CVE-2025-66499: Foxit PDF Editor
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data. An integer overflow in the calculation of the image buffer size may occur, potentially allowing a remote attacker to execute arbitrary code.
Affected products
- Foxit PDF Editor: up to and including 13.2.1.23955; from 14.0.0.33046, up to and including 14.0.1.33197; from 2023.1.0.15510, up to and including 2023.3.0.23028; from 2024.1.0.23997, up to and including 2024.4.1.27687; from 2025.1.0.27937, up to and including 2025.2.1.33197; up to and including 13.2.1.63315; …
- Foxit PDF Reader: up to and including 2025.2.1.33197; up to and including 2025.2.1.69005
Published 2025-12-19. Last modified 2026-06-17.