← Vulnerability feed

Vulnerability record · CVE-2012-5340 · published 23 January 2020

CVE-2012-5340: Sumatrapdfreader sumatrapdf integer overflow vulnerability

Sumatrapdfreader · Sumatrapdf

SumatraPDF 2.1.1/MuPDF 1.0 allows remote attackers to cause an Integer Overflow in the lex_number() function via a corrupt PDF file.

7.8 CVSS 3.1 High EPSS 5.7% · top 7.2% CWE-190 · Integer overflow
7.8CVSS 3.1 base score, v2 6.8
5.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

SumatraPDF 2.1.1/MuPDF 1.0 allows remote attackers to cause an Integer Overflow in the lex_number() function via a corrupt PDF file.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-5340 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-7321Artifex mupdf out-of-bounds write vulnerabilityUsage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 1.14 can result in a heap overflow vulnerability that allows an atta…EPSS 3.2%9.8CVE-2016-6525Debian linux memory buffer overflow vulnerabilityHeap-based buffer overflow in the pdf_load_mesh_params function in pdf/pdf-shade.c in MuPDF allows remote attackers to cause a denial of service (cra…EPSS 3.8%9.3CVE-2012-4895Sumatrapdfreader sumatrapdf memory buffer overflow vulnerabilityHeap-based buffer overflow in SumatraPDF before 2.1 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnera…EPSS 5.2%9.3CVE-2012-4896Sumatrapdfreader sumatrapdf memory buffer overflow vulnerabilityHeap-based buffer overflow in SumatraPDF before 2.1 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnera…EPSS 5.2%9.3CVE-2011-0341Artifex mupdf memory buffer overflow vulnerabilityStack-based buffer overflow in the pdfmoz_onmouse function in apps/mozilla/moz_main.c in the MuPDF plug-in 2008.09.02 for Firefox allows remote attac…EPSS 3.8%9.3CVE-2009-4117Sumatrapdfreader sumatrapdf memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in pdf_shade4.c in MuPDF before commit 20091125231942, as used in SumatraPDF before 1.0.1, allow remote attacke…EPSS 7.8%7.8CVE-2026-25880Sumatrapdfreader sumatrapdf untrusted search path vulnerabilitySumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, the PDF reader allows execution of a malicious binary (explorer.exe) located i…EPSS 0.20%7.8CVE-2026-23512Sumatrapdfreader sumatrapdf untrusted search path vulnerabilitySumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search Path vulnerability when Advanced Options setting i…EPSS 0.22%

Source: NIST National Vulnerability Database (record CVE-2012-5340), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.