Summary
Detail | |||
---|---|---|---|
Vendor | Sumatrapdfreader | First view | 2009-05-11 |
Product | Sumatrapdf | Last view | 2023-07-26 |
Version | Type | Application | |
Update | |||
Edition | |||
Language | |||
Sofware Edition | |||
Target Software | |||
Target Hardware | |||
Other |
Activity : Overall
COMMON PLATFORM ENUMERATION: Repartition per Version
Related : CVE
Date | Alert | Description | |
---|---|---|---|
5.5 | 2023-07-26 | CVE-2023-33802 | A buffer overflow in SumatraPDF Reader v3.4.6 allows attackers to cause a Denial of Service (DoS) via a crafted text file. |
7.8 | 2020-01-23 | CVE-2012-5340 | SumatraPDF 2.1.1/MuPDF 1.0 allows remote attackers to cause an Integer Overflow in the lex_number() function via a corrupt PDF file. |
7.8 | 2018-02-08 | CVE-2013-2830 | Use-after-free vulnerability in SumatraPDF Reader 2.x before 2.2.1 allows remote attackers to execute arbitrary code via a crafted PDF file. |
9.3 | 2012-10-05 | CVE-2012-4896 | Heap-based buffer overflow in SumatraPDF before 2.1 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2012-4895. |
9.3 | 2012-10-05 | CVE-2012-4895 | Heap-based buffer overflow in SumatraPDF before 2.1 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2012-4896. |
9.3 | 2009-11-30 | CVE-2009-4117 | Multiple stack-based buffer overflows in pdf_shade4.c in MuPDF before commit 20091125231942, as used in SumatraPDF before 1.0.1, allow remote attackers to cause a denial of service and possibly execute arbitrary code via a /Decode array for certain types of shading that are not properly handled by the (1) pdf_loadtype4shade, (2) pdf_loadtype5shade, (3) pdf_loadtype6shade, and (4) pdf_loadtype7shade functions. NOTE: some of these details are obtained from third party information. |
9.3 | 2009-05-11 | CVE-2009-1605 | Heap-based buffer overflow in the loadexponentialfunc function in mupdf/pdf_function.c in MuPDF in the mupdf-20090223-win32 package, as used in SumatraPDF 0.9.3 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF file. NOTE: some of these details are obtained from third party information. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
57% (4) | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
14% (1) | CWE-416 | Use After Free |
14% (1) | CWE-190 | Integer Overflow or Wraparound |
14% (1) | CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflo... |
Open Source Vulnerability Database (OSVDB)
id | Description |
---|---|
60609 | MuPDF mupdf/pdf_shade4.c Multiple Function PDF File Handling Overflow |
54104 | MuPDF pdf_function.c loadexponentialfunc() Function Overflow |
ExploitDB Exploits
id | Description |
---|---|
23246 | Sumatra 2.1.1/MuPDF 1.0 Integer Overflow |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2012-10-02 | Name: The remote Windows host has a PDF reader installed that is affected by multip... File: sumatra_pdf_21.nasl - Type: ACT_GATHER_INFO |