Vulnerability Description
A NULL pointer dereference vulnerability in the util.readFileIntoStream component of PDF-XChange Editor v10.7.3.401 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pdf-Xchange | Pdf-Xchange Editor | 10.7.3.401 |
Related Weaknesses (CWE)
References
- https://jeroscope.com/advisories/2025/jero-2025-011/ExploitThird Party Advisory
- https://www.pdf-xchange.com/Product
FAQ
What is CVE-2025-64086?
CVE-2025-64086 is a vulnerability with a CVSS score of 7.5 (HIGH). A NULL pointer dereference vulnerability in the util.readFileIntoStream component of PDF-XChange Editor v10.7.3.401 allows attackers to cause a Denial of Service (DoS) via a crafted input.
How severe is CVE-2025-64086?
CVE-2025-64086 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-64086?
Check the references section above for vendor advisories and patch information. Affected products include: Pdf-Xchange Pdf-Xchange Editor.