The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary code execution.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Apr 2026 04:30:00 +0000


Wed, 01 Apr 2026 02:15:00 +0000

Type Values Removed Values Added
Description The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary code execution.
Title Foxit PDF Editor/Reader List Box Calculate Array Use-After-Free Vulnerability
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-04-02T02:14:05.708Z

Reserved: 2026-03-08T03:43:28.979Z

Link: CVE-2026-3779

cve-icon Vulnrichment

Updated: 2026-04-01T03:06:18.215Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-01T02:16:03.043

Modified: 2026-04-01T14:23:37.727

Link: CVE-2026-3779

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses