7.3

CVE-2025-57248

Exploit
A null pointer dereference vulnerability was discovered in SumatraPDF 3.5.2 during the processing of a crafted .djvu file. When the file is opened, the application crashes inside libmupdf.dll, specifically in the DataPool::has_data() function.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sumatrapdfreader ≫ Sumatrapdf Version 3.5.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.159
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.3 3.9 3.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://github.com/sumatrapdfreader/sumatrapdf/issues/5035
Patch
Exploit
Issue Tracking