SumatraPDF 是一款面向 Windows 系统的多格式文档阅读器。在 3.6.1 及更早版本中, 函数在处理 命令时,会向 传递一个空的当前选项卡指针,随后该函数解引用 成员。当没有打开任何文档选项卡时,同一交互式 Windows 会话中的本地进程(其完整性级别等于或高于 SumatraPDF 的完整性级别,且受 Windows UIPI 保护机制约束)可通过 DDE(动态数据交换)或 消息发送 命令,从而导致 SumatraPDF 进程异常终止,并造成未保存状态的丢失。该漏洞的影响范围仅限于 adviso
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sumatrapdfreader | sumatrapdf | <= 3.6.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107732 | 8.4 HIGH | SumatraPDF: Markup/command-link injection into UI notification text |
| CVE-2026-107734 | 7.1 HIGH | SumatraPDF: SyncTeX Argument Injection in Inverse Search Enables Arbitrary Command Executi |
| CVE-2026-107802 | 7.1 HIGH | SumatraPDF — Windows command-line argument injection in AI selection-translate |
| CVE-2026-107736 | 6.8 MEDIUM | SumatraPDF: stack buffer overflow while processing EXIF Orientation metadata |
| CVE-2026-107738 | 6.8 MEDIUM | SumatraPDF: Untrusted binary record offset used without lower-bound validation |
| CVE-2026-107737 | 5.7 MEDIUM | SumatraPDF CHM `its://` signed index causes an out-of-bounds object lookup |
| CVE-2026-107731 | 5.5 MEDIUM | SumatraPDF: LIT parser range-validation flaws cause invalid-pointer reads and denial of se |
| CVE-2026-107729 | 5.5 MEDIUM | SumatraPDF: Unsigned-to-signed hdrLen validation bypass in SumatraPDF MOBI parsing causes |
| CVE-2026-107730 | 5.5 MEDIUM | SumatraPDF: Signed integer overflow in the LIT header parsing causes invalid-pointer read |
| CVE-2026-107735 | 5.4 MEDIUM | SumatraPDF: `sumatrapdfrestrict.ini` never revokes any permission (fail-open policy initia |
No comments yet