Skip to main content

Vendor/product archive

gonitro / nitro_pro CVEs

Beta · best-effort

18 CVEs tagged to gonitro / nitro_pro0 Critical, 14 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2021-21797

Published Oct 18, 2021

An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference to a timeout object to be sto…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-21796

Published Oct 18, 2021

An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an object containing the path to a doc…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-21798

Published Sep 15, 2021

An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a stack variable to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6116

Published Sep 17, 2020

An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. When drawing the contents of a page using colors f…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6115

Published Sep 17, 2020

An exploitable vulnerability exists in the cross-reference table repairing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. While searching for an object identifier…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6113

Published Sep 17, 2020

An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when updating its cross-reference table. When proces…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6112

Published Sep 17, 2020

An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when decoding sub-samples. While i…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6146

Published Sep 16, 2020

An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300. When drawing the contents of a page and selecting the s…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6093

Published May 18, 2020

An exploitable information disclosure vulnerability exists in the way Nitro Pro 13.9.1.155 does XML error handling. A specially crafted PDF document can cause uninitialized memory…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-6092

Published May 18, 2020

An exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects. A specially crafted PDF file can trigger an integer overflow that can le…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-6074

Published May 18, 2020

An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF document can cause a use-after-free which can lead to remote…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-10223

Published Mar 8, 2020

npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPDAnnotHandlerUtils::create_popup_for_markup+0x12fbe via a cr…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10222

Published Mar 8, 2020

npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to Heap Corruption at npdf!nitro::get_property+2381 via a crafted PDF document.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18958

Published Nov 21, 2019

Nitro Pro before 13.2 creates a debug.log file in the directory where a .pdf file is located, if the .pdf document was produced by an OCR operation on the JPEG output of a scanner…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7442

Published Aug 3, 2017

Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7950

Published Jul 7, 2017

Nitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1