SumatraPDF 是 Windows 平台上的一款多格式文档阅读器。在版本 3.6.1 及更早版本中, 函数在初始化时,会将 配置文件的路径与 变量(初始值设为 ,即允许所有权限)结合,并且仅通过逻辑“或”(OR)操作来合并权限位。这种实现方式导致 INI 文件中的权限限制配置无法实际撤销任何权限。因此,如果通过该 INI 文件部署 SumatraPDF,无论配置文件是否存在格式错误,还是权限设置值为零,均可能导致磁盘访问、网络、打印、注册表、剪贴板、偏好设置以及全屏模式等方面的策略限制被静默绕过。 需要注意的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sumatrapdfreader | sumatrapdf | <= 3.6.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107732 | 8.4 HIGH | SumatraPDF: Markup/command-link injection into UI notification text |
| CVE-2026-107734 | 7.1 HIGH | SumatraPDF: SyncTeX Argument Injection in Inverse Search Enables Arbitrary Command Executi |
| CVE-2026-107802 | 7.1 HIGH | SumatraPDF — Windows command-line argument injection in AI selection-translate |
| CVE-2026-107733 | 6.8 MEDIUM | SumatraPDF: Null-pointer dereference in `CmdExec` when no document tab is open |
| CVE-2026-107736 | 6.8 MEDIUM | SumatraPDF: stack buffer overflow while processing EXIF Orientation metadata |
| CVE-2026-107738 | 6.8 MEDIUM | SumatraPDF: Untrusted binary record offset used without lower-bound validation |
| CVE-2026-107737 | 5.7 MEDIUM | SumatraPDF CHM `its://` signed index causes an out-of-bounds object lookup |
| CVE-2026-107731 | 5.5 MEDIUM | SumatraPDF: LIT parser range-validation flaws cause invalid-pointer reads and denial of se |
| CVE-2026-107729 | 5.5 MEDIUM | SumatraPDF: Unsigned-to-signed hdrLen validation bypass in SumatraPDF MOBI parsing causes |
| CVE-2026-107730 | 5.5 MEDIUM | SumatraPDF: Signed integer overflow in the LIT header parsing causes invalid-pointer read |
No comments yet