SumatraPDF 是一款适用于 Windows 的多格式文档阅读器。在版本 3.6.1 及更早版本中,ChmFile::GetCharZ() 函数将来自“/#WINDOWS”和“/#IVB”段的、由文件控制的无符号字符串偏移量直接窄化(narrow)为有符号整数,且未进行下界检查。当该偏移量被转换为负值时,会导致函数在“/#STRINGS”缓冲区之前进行读取,从而引发确定性的应用程序终止。除该漏洞说明中所述条件外,未宣称存在更广泛的安全影响。截至本次评审,尚未发布修复该问题的版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sumatrapdfreader | sumatrapdf | <= 3.6.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107732 | 8.4 HIGH | SumatraPDF: Markup/command-link injection into UI notification text |
| CVE-2026-107734 | 7.1 HIGH | SumatraPDF: SyncTeX Argument Injection in Inverse Search Enables Arbitrary Command Executi |
| CVE-2026-107802 | 7.1 HIGH | SumatraPDF — Windows command-line argument injection in AI selection-translate |
| CVE-2026-107733 | 6.8 MEDIUM | SumatraPDF: Null-pointer dereference in `CmdExec` when no document tab is open |
| CVE-2026-107736 | 6.8 MEDIUM | SumatraPDF: stack buffer overflow while processing EXIF Orientation metadata |
| CVE-2026-107737 | 5.7 MEDIUM | SumatraPDF CHM `its://` signed index causes an out-of-bounds object lookup |
| CVE-2026-107731 | 5.5 MEDIUM | SumatraPDF: LIT parser range-validation flaws cause invalid-pointer reads and denial of se |
| CVE-2026-107729 | 5.5 MEDIUM | SumatraPDF: Unsigned-to-signed hdrLen validation bypass in SumatraPDF MOBI parsing causes |
| CVE-2026-107730 | 5.5 MEDIUM | SumatraPDF: Signed integer overflow in the LIT header parsing causes invalid-pointer read |
| CVE-2026-107735 | 5.4 MEDIUM | SumatraPDF: `sumatrapdfrestrict.ini` never revokes any permission (fail-open policy initia |
No comments yet