SumatraPDF 是 Windows 平台上的多格式文档阅读器。在版本 3.5.2 及更早版本中,攻击者可控的 SyncTeX 源文件名会被直接替换到外部编辑器命令行中的 占位符处,且未采用安全的 Windows 参数引号转义方式。最终构造的命令行被传递给 函数执行。当用户已配置或自动检测到外部编辑器,并打开一个包含精心构造的 文件的 PDF 文档并触发反向搜索功能时,攻击者可在命令行中注入额外参数。该漏洞的实际影响取决于目标编辑器对这些参数的解析行为,可能导致非预期的编辑器操作,或通过恶意扩展实现代码执行。除
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sumatrapdfreader | sumatrapdf | <= 3.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107732 | 8.4 HIGH | SumatraPDF: Markup/command-link injection into UI notification text |
| CVE-2026-107802 | 7.1 HIGH | SumatraPDF — Windows command-line argument injection in AI selection-translate |
| CVE-2026-107733 | 6.8 MEDIUM | SumatraPDF: Null-pointer dereference in `CmdExec` when no document tab is open |
| CVE-2026-107736 | 6.8 MEDIUM | SumatraPDF: stack buffer overflow while processing EXIF Orientation metadata |
| CVE-2026-107738 | 6.8 MEDIUM | SumatraPDF: Untrusted binary record offset used without lower-bound validation |
| CVE-2026-107737 | 5.7 MEDIUM | SumatraPDF CHM `its://` signed index causes an out-of-bounds object lookup |
| CVE-2026-107731 | 5.5 MEDIUM | SumatraPDF: LIT parser range-validation flaws cause invalid-pointer reads and denial of se |
| CVE-2026-107729 | 5.5 MEDIUM | SumatraPDF: Unsigned-to-signed hdrLen validation bypass in SumatraPDF MOBI parsing causes |
| CVE-2026-107730 | 5.5 MEDIUM | SumatraPDF: Signed integer overflow in the LIT header parsing causes invalid-pointer read |
| CVE-2026-107735 | 5.4 MEDIUM | SumatraPDF: `sumatrapdfrestrict.ini` never revokes any permission (fail-open policy initia |
No comments yet