CVE-2026-107733 | SumatraPDF up to 3.6.1 DDE FrameOnCommand null pointer dereference

SecurityVulns

A vulnerability marked as problematic has been reported in SumatraPDF up to 3.6.1. The affected element is the function FrameOnCommand of the component DDE Handler. The manipulation leads to null pointer dereference.

This vulnerability is referenced as CVE-2026-107733. The attack can only be performed from a local environment. No exploit is available.VulDB Recent EntriesRead More