CVE-2025-64085: Null Pointer Dereference
Published Dec 9, 2025
·Updated
A NULL pointer dereference vulnerability in the importDataObject() function of PDF-XChange Editor v10.7.3.401 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Affected Software
2 affected components
Tracker Software PDF-XChange Editor
PDF-XChange PDF-XChange Editor=10.7.3.401
Event History
Dec 9, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-64085?
CVE-2025-64085 is classified as a high-severity vulnerability due to its potential to cause Denial of Service (DoS).
2
How do I fix CVE-2025-64085?
To mitigate CVE-2025-64085, update PDF-XChange Editor to version 10.7.3.402 or later, which contains the security patch.
3
What kind of attack does CVE-2025-64085 facilitate?
CVE-2025-64085 enables attackers to cause a Denial of Service (DoS) by exploiting a NULL pointer dereference vulnerability.
4
Which software versions are affected by CVE-2025-64085?
CVE-2025-64085 affects Tracker Software PDF-XChange Editor version 10.7.3.401.
5
Can CVE-2025-64085 be exploited remotely?
Yes, CVE-2025-64085 can be exploited remotely through crafted input sent to the affected version of PDF-XChange Editor.