← Vulnerability feed

Vulnerability record · CVE-2009-4117 · published 1 December 2009

CVE-2009-4117: Sumatrapdfreader sumatrapdf memory buffer overflow vulnerability

Sumatrapdfreader · Sumatrapdf

Multiple stack-based buffer overflows in pdf_shade4.c in MuPDF before commit 20091125231942, as used in SumatraPDF before 1.0.1, allow remote attackers to cause a denial of service and possibly execute arbitrary code via a /Decode array for certain types of shading that are not properly handled by the (1) pdf_loadtype4shade, (2) pdf_loadtype5shade, (3) pdf_loadtype6shade, and (4) pdf_loadtype7shade functions. NOTE: some of these details are obtained from third party information.

9.3 CVSS 2.0 High EPSS 7.8% · top 5.6% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
7.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
15References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in pdf_shade4.c in MuPDF before commit 20091125231942, as used in SumatraPDF before 1.0.1, allow remote attackers to cause a denial of service and possibly execute arbitrary code via a /Decode array for certain types of shading that are not properly handled by the (1) pdf_loadtype4shade, (2) pdf_loadtype5shade, (3) pdf_loadtype6shade, and (4) pdf_loadtype7shade functions. NOTE: some of these details are obtained from third party information.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-4117 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2012-4895Sumatrapdfreader sumatrapdf memory buffer overflow vulnerabilityHeap-based buffer overflow in SumatraPDF before 2.1 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnera…EPSS 5.2%9.3CVE-2012-4896Sumatrapdfreader sumatrapdf memory buffer overflow vulnerabilityHeap-based buffer overflow in SumatraPDF before 2.1 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnera…EPSS 5.2%7.8CVE-2026-25880Sumatrapdfreader sumatrapdf untrusted search path vulnerabilitySumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, the PDF reader allows execution of a malicious binary (explorer.exe) located i…EPSS 0.20%7.8CVE-2026-23512Sumatrapdfreader sumatrapdf untrusted search path vulnerabilitySumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search Path vulnerability when Advanced Options setting i…EPSS 0.22%7.8CVE-2012-5340Sumatrapdfreader sumatrapdf integer overflow vulnerabilitySumatraPDF 2.1.1/MuPDF 1.0 allows remote attackers to cause an Integer Overflow in the lex_number() function via a corrupt PDF file.EPSS 5.7%7.8CVE-2013-2830Sumatrapdfreader sumatrapdf use after free vulnerabilityUse-after-free vulnerability in SumatraPDF Reader 2.x before 2.2.1 allows remote attackers to execute arbitrary code via a crafted PDF file.EPSS 3.6%7.5CVE-2026-25961Sumatrapdfreader sumatrapdf improper certificate validation vulnerabilitySumatraPDF is a multi-format reader for Windows. In 3.5.0 through 3.5.2, SumatraPDF's update mechanism disables TLS hostname verification (INTERNET_F…EPSS 0.44%7.3CVE-2025-57248Sumatrapdfreader sumatrapdf null pointer dereference vulnerabilityA null pointer dereference vulnerability was discovered in SumatraPDF 3.5.2 during the processing of a crafted .djvu file. When the file is opened, t…EPSS 0.24%

Source: NIST National Vulnerability Database (record CVE-2009-4117), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.