📦 Sumatrapdf

by Sumatrapdfreader

🔍 What is Sumatrapdf?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-25961

HIGH CVSS 7.5 Feb 9, 2026

This vulnerability allows network attackers to intercept SumatraPDF's update requests and deliver malicious installers due to disabled TLS hostname verification and missing signature checks. Attackers...

CVE-2026-25880

HIGH CVSS 7.8 Feb 9, 2026

SumatraPDF versions 3.5.2 and earlier contain a vulnerability where clicking 'Show in folder' in the File menu executes explorer.exe from the same directory as the opened PDF file. This allows attacke...

CVE-2026-23512

HIGH CVSS 8.6 Jan 14, 2026

SumatraPDF versions 3.5.2 and earlier contain an untrusted search path vulnerability that allows arbitrary code execution. When users trigger the Advanced Options setting, the application executes not...

CVE-2025-57248

HIGH CVSS 7.3 Sep 15, 2025

A null pointer dereference vulnerability in SumatraPDF 3.5.2 allows attackers to crash the application by tricking users into opening a malicious .djvu file. This affects all users running the vulnera...

CVE-2026-25920

MEDIUM CVSS 5.5 Feb 9, 2026

A heap out-of-bounds read vulnerability in SumatraPDF's MOBI HuffDic decompressor allows reading beyond allocated memory bounds when processing malicious .mobi files. This affects all users of Sumatra...

CVE-2026-23951

MEDIUM CVSS 5.5 Jan 22, 2026

SumatraPDF contains an off-by-one error when processing specially crafted Mobi files, causing an integer underflow that leads to an out-of-bounds heap read and application crash. This affects all Wind...