Sumatrapdfreader is a lightweight, open-source PDF viewer whose relatively compact attack surface belies its prominence in the vulnerability landscape, driven by widespread deployment as a portable alternative to larger document-readers. Its disclosed vulnerabilities concentrate in the core Sumatrapdf product and recur through memory-safety and input-validation weakness classes—buffer overflows, out-of-bounds reads, improper bounds checking, and untrusted search-path issues—that are typical of native C/C++ document parsers, and the product has a notable tendency to acquire public exploit code. Defenders should prioritize this vendor's updates for systems where document-opening is a frequent user activity; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sumatrapdfreader over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-5340HIGH SumatraPDF 2.1.1/MuPDF 1.0 allows remote attackers to cause an Integer Overflow in the lex_number() function via a corrupt PDF file. | Jan 23, 2020 | 7.8 | 37 | NO | YES |
CVE-2009-4117HIGH Multiple stack-based buffer overflows in pdf_shade4.c in MuPDF before commit 20091125231942, as used in SumatraPDF before 1.0.1, allow remote attackers to cause a denial of service | Dec 1, 2009 | 9.3 | 36 | NO | YES |
CVE-2026-25961HIGH SumatraPDF is a multi-format reader for Windows. In 3.5.0 through 3.5.2, SumatraPDF's update mechanism disables TLS hostname verification (INTERNET_FLAG_IGNORE_CERT_CN_INVALID) and | Feb 9, 2026 | 7.5 | 35 | NO | YES |
CVE-2026-23512HIGH SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search Path vulnerability when Advanced Options setting is trigger. The application exec | Jan 14, 2026 | 7.8 | 29 | NO | NO |
CVE-2012-4896HIGH Heap-based buffer overflow in SumatraPDF before 2.1 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2012-4895. | Oct 5, 2012 | 9.3 | 29 | NO | NO |
CVE-2012-4895HIGH Heap-based buffer overflow in SumatraPDF before 2.1 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2012-4896. | Oct 5, 2012 | 9.3 | 29 | NO | NO |
CVE-2026-25880HIGH SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, the PDF reader allows execution of a malicious binary (explorer.exe) located in the same directory as the ope | Feb 9, 2026 | 7.8 | 26 | NO | NO |
CVE-2026-23951MEDIUM SumatraPDF is a multi-format reader for Windows. All versions contain an off-by-one error in the validation code that only triggers with exactly 2 records, causing an integer under | Jan 22, 2026 | 5.5 | 23 | NO | NO |
CVE-2025-57248HIGH A null pointer dereference vulnerability was discovered in SumatraPDF 3.5.2 during the processing of a crafted .djvu file. When the file is opened, the application crashes inside l | Sep 15, 2025 | 7.3 | 23 | NO | NO |
CVE-2013-2830HIGH Use-after-free vulnerability in SumatraPDF Reader 2.x before 2.2.1 allows remote attackers to execute arbitrary code via a crafted PDF file. | Feb 8, 2018 | 7.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sumatrapdfreader.
Media articles that mention a CVE ID that affects a product developed by Sumatrapdfreader — matched by CVE ID, not by vendor name.