SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, and in pre-release 3.7.0.20369 when WebView2 is absent or cannot initialize, ParseProtoUrl() accepts the signed host component of an its:// URL and FindHtmlWindowById() uses it directly as an index into gHtmlWindows. Opening a crafted CHM through the IE fallback backend with a negative or otherwise out-of-range window identifier can cause an out-of-bounds pointer read followed by an invalid object callback dereference and process termination. No fixed version is available as of this review.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sumatrapdfreader
Sumatrapdfreader sumatrapdf |
|
| Vendors & Products |
Sumatrapdfreader
Sumatrapdfreader sumatrapdf |
Thu, 08 Oct 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, and in pre-release 3.7.0.20369 when WebView2 is absent or cannot initialize, ParseProtoUrl() accepts the signed host component of an its:// URL and FindHtmlWindowById() uses it directly as an index into gHtmlWindows. Opening a crafted CHM through the IE fallback backend with a negative or otherwise out-of-range window identifier can cause an out-of-bounds pointer read followed by an invalid object callback dereference and process termination. No fixed version is available as of this review. | |
| Title | SumatraPDF CHM `its://` signed index causes an out-of-bounds object lookup | |
| Weaknesses | CWE-129 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-08T22:34:16.436Z
Reserved: 2026-10-08T17:21:52.977Z
Link: CVE-2026-107737
No data.
Status : Deferred
Published: 2026-10-08T23:16:59.760
Modified: 2026-10-08T23:16:59.900
Link: CVE-2026-107737
No data.
OpenCVE Enrichment
Updated: 2026-10-08T23:30:12Z
Weaknesses