SumatraPDF 是一款面向 Windows 系统的多格式文档阅读器。在版本 3.7.0.22298 中,src/MobiDoc.cpp 对不受信任的无符号字段 mobiHdr.hdrLen 进行验证时,将其窄转换为有符号整数;当该字段值超过 INT_MAX 时,会被转换为负数,从而绕过上限检查。当 EXTH 标志位被设置时,原始无符号值被重新用作指针偏移量,导致 DecodeExthHeader() 函数读取超出记录缓冲区的内存。打开精心构造的 MOBI 文件可可靠地导致应用程序终止,并引发本机访问违规异常;
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sumatrapdfreader | sumatrapdf | <= 3.7.0.22298 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107732 | 8.4 HIGH | SumatraPDF: Markup/command-link injection into UI notification text |
| CVE-2026-107734 | 7.1 HIGH | SumatraPDF: SyncTeX Argument Injection in Inverse Search Enables Arbitrary Command Executi |
| CVE-2026-107802 | 7.1 HIGH | SumatraPDF — Windows command-line argument injection in AI selection-translate |
| CVE-2026-107733 | 6.8 MEDIUM | SumatraPDF: Null-pointer dereference in `CmdExec` when no document tab is open |
| CVE-2026-107736 | 6.8 MEDIUM | SumatraPDF: stack buffer overflow while processing EXIF Orientation metadata |
| CVE-2026-107738 | 6.8 MEDIUM | SumatraPDF: Untrusted binary record offset used without lower-bound validation |
| CVE-2026-107737 | 5.7 MEDIUM | SumatraPDF CHM `its://` signed index causes an out-of-bounds object lookup |
| CVE-2026-107731 | 5.5 MEDIUM | SumatraPDF: LIT parser range-validation flaws cause invalid-pointer reads and denial of se |
| CVE-2026-107730 | 5.5 MEDIUM | SumatraPDF: Signed integer overflow in the LIT header parsing causes invalid-pointer read |
| CVE-2026-107735 | 5.4 MEDIUM | SumatraPDF: `sumatrapdfrestrict.ini` never revokes any permission (fail-open policy initia |
No comments yet