Skip to main content

Vendor archive

gonitro CVEs

Beta · best-effort

35 CVEs tagged to vendor gonitro0 Critical, 27 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2025-69627

Published Apr 13, 2026

Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript method this.mailDoc(). During execution, an internal XID o…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-69624

Published Apr 13, 2026

Nitro PDF Pro before 14.43 for Windows contains a NULL pointer dereference vulnerability in the JavaScript implementation of app.alert(). When app.alert() is called with more than…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-67825

Published Jan 8, 2026

An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information from a non-verified PDF field rather than from the verifie…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21797

Published Oct 18, 2021

An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference to a timeout object to be sto…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-21796

Published Oct 18, 2021

An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an object containing the path to a doc…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-21798

Published Sep 15, 2021

An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a stack variable to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6116

Published Sep 17, 2020

An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. When drawing the contents of a page using colors f…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6115

Published Sep 17, 2020

An exploitable vulnerability exists in the cross-reference table repairing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. While searching for an object identifier…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6113

Published Sep 17, 2020

An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when updating its cross-reference table. When proces…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6112

Published Sep 17, 2020

An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when decoding sub-samples. While i…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6146

Published Sep 16, 2020

An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300. When drawing the contents of a page and selecting the s…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6093

Published May 18, 2020

An exploitable information disclosure vulnerability exists in the way Nitro Pro 13.9.1.155 does XML error handling. A specially crafted PDF document can cause uninitialized memory…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-6092

Published May 18, 2020

An exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects. A specially crafted PDF file can trigger an integer overflow that can le…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-6074

Published May 18, 2020

An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF document can cause a use-after-free which can lead to remote…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-10223

Published Mar 8, 2020

npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPDAnnotHandlerUtils::create_popup_for_markup+0x12fbe via a cr…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10222

Published Mar 8, 2020

npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to Heap Corruption at npdf!nitro::get_property+2381 via a crafted PDF document.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2013-2773

Published Jan 14, 2020

Nitro PDF 8.5.0.26: A specially crafted DLL file can facilitate Arbitrary Code Execution

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19819

Published Jan 10, 2020

The JBIG2Globals library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x90ec NULL Pointer Dereference via crafted Unico…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19817

Published Jan 10, 2020

The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x2e8a Out-of-Bounds Read via crafted Unicode cont…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19818

Published Dec 16, 2019

The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0xa08a Out-of-Bounds Read via crafted Unicode cont…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18958

Published Nov 21, 2019

Nitro Pro before 13.2 creates a debug.log file in the directory where a .pdf file is located, if the .pdf document was produced by an OCR operation on the JPEG output of a scanner…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5053

Published Oct 9, 2019

An exploitable use-after-free vulnerability exists in the Length parsing function of NitroPDF. A specially crafted PDF can cause a type confusion, resulting in a use-after-free co…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 35 CVEsPage 1 of 2