Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

sumatrapdfreader — Vulnerabilities & Security Advisories 18

Browse all 18 CVE security advisories affecting sumatrapdfreader. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SumatraPDF Reader serves as a lightweight PDF viewer for Windows, prioritizing speed and minimal resource usage. Historically, it has been susceptible to multiple remote code execution vulnerabilities, often through crafted PDF files leveraging buffer overflows or parsing flaws. Other common issues include cross-site scripting and privilege escalation flaws. The application's small codebase and infrequent updates have contributed to security gaps, with five CVEs recorded to date. While no major public incidents have been widely reported, the consistent pattern of vulnerabilities in document parsing highlights risks for users handling untrusted PDF content, particularly in environments where security is a primary concern.

Top products by sumatrapdfreader: sumatrapdf
CVE ID Title CVSS Severity Published
CVE-2026-107802 SumatraPDF — Windows command-line argument injection in AI selection-translate — sumatrapdf CWE-88 7.1 High 2026-10-08
CVE-2026-107738 SumatraPDF: Untrusted binary record offset used without lower-bound validation — sumatrapdf CWE-125 6.8 Medium 2026-10-08
CVE-2026-107737 SumatraPDF CHM `its://` signed index causes an out-of-bounds object lookup — sumatrapdf CWE-129 5.7 Medium 2026-10-08
CVE-2026-107736 SumatraPDF: stack buffer overflow while processing EXIF Orientation metadata — sumatrapdf CWE-121 6.8 Medium 2026-10-08
CVE-2026-107735 SumatraPDF: `sumatrapdfrestrict.ini` never revokes any permission (fail-open policy initialization) — sumatrapdf CWE-636 5.4 Medium 2026-10-08
CVE-2026-107734 SumatraPDF: SyncTeX Argument Injection in Inverse Search Enables Arbitrary Command Execution via External Editors — sumatrapdf CWE-20 7.1 High 2026-10-08
CVE-2026-107733 SumatraPDF: Null-pointer dereference in `CmdExec` when no document tab is open — sumatrapdf CWE-476 6.8 Medium 2026-10-08
CVE-2026-107732 SumatraPDF: Markup/command-link injection into UI notification text — sumatrapdf CWE-94 8.4 High 2026-10-08
CVE-2026-107731 SumatraPDF: LIT parser range-validation flaws cause invalid-pointer reads and denial of service — sumatrapdf CWE-125 5.5 Medium 2026-10-08
CVE-2026-107730 SumatraPDF: Signed integer overflow in the LIT header parsing causes invalid-pointer read — sumatrapdf CWE-190 5.5 Medium 2026-10-08
CVE-2026-107729 SumatraPDF: Unsigned-to-signed hdrLen validation bypass in SumatraPDF MOBI parsing causes out-of-bounds read — sumatrapdf CWE-125 5.5 Medium 2026-10-08
CVE-2026-26054 SumatraPDF: Heap out-of-bounds read in MOBI header parser. — sumatrapdf CWE-125 6.8 Medium 2026-09-24
CVE-2026-55586 SumatraPDF: Heap out-of-bounds write in vendored CHMLib LZX Huffman table construction reachable from crafted CHM files — sumatrapdf CWE-119 6.6 Medium 2026-08-20
CVE-2026-25961 SumatraPDF Update MITM -> Arbitrary Code Execution — sumatrapdf CWE-295 7.5 High 2026-02-09
CVE-2026-25920 SumatraPDF has a heap out-of-bounds read in MOBI HuffDic decompressor — sumatrapdf CWE-125 5.5 Medium 2026-02-09
CVE-2026-25880 Untrusted Search Path in SumatraPDF Reader (explorer.exe on Windows) — sumatrapdf CWE-426 7.8 High 2026-02-09
CVE-2026-23951 SumatraPDF's Integer Underflow in PalmDbReader Leads to Crash — sumatrapdf CWE-125 5.5 Medium 2026-01-22
CVE-2026-23512 SumatraPDF has an Untrusted Search Path in sumatrapdf/src/AppTools.cpp — sumatrapdf CWE-426 8.6 High 2026-01-14

This page lists every published CVE security advisory associated with sumatrapdfreader. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.