Vulnerabilities > CVE-2022-26979 - NULL Pointer Dereference vulnerability in Foxit PDF Editor and PDF Reader

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
foxit
CWE-476

Summary

Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL.

Common Weakness Enumeration (CWE)