Use-After-Free Vulnerability in PDF-XChange Editor by Tracker Software
CVE-2025-6646

3.3LOW

Key Information:

Vendor
CVE Published:
25 June 2025

What is CVE-2025-6646?

A vulnerability in PDF-XChange Editor's handling of U3D file parsing can allow attackers to disclose sensitive information. The flaw arises from improper validation of object existence before executing operations, potentially leading to exploitation when a user interacts with malicious content. By visiting a compromised page or opening a crafted file, an attacker could exploit this issue to disclose sensitive information. This vulnerability may also be leveraged alongside other vulnerabilities to execute arbitrary code within the context of the affected application.

Affected Version(s)

PDF-XChange Editor 10.5.2.395

References

CVSS V3.0

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-6646 : Use-After-Free Vulnerability in PDF-XChange Editor by Tracker Software