CVE-2026-57256

Published Jul 8, 2026

Last updated 2 months ago

Overview

Description
When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and this operation is repeated after the form is reset. During this process, the application failed to adequately verify the validity of the form objects and their internal dictionary pointers, resulting in accessing internal members of invalid or improperly initialized fields. This led to an illegal pointer read, ultimately causing the application to crash.
Source
14984358-7092-470d-8f34-ade47a7658a2
NVD status
Modified
Products
pdf_editor, pdf_reader

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

14984358-7092-470d-8f34-ade47a7658a2
CWE-416

Social media

Hype score
Not currently trending

Configurations