VYPR

Pro

by Nitro

CVEs (13)

  • CVE-2020-6146HigSep 16, 2020
    risk 0.63cvss 8.8epss 0.77

    An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300. When drawing the contents of a page and selecting the stroke color from an 'ICCBased' colorspace, the application will read a length from the file and use…

  • CVE-2020-10223HigMar 8, 2020
    risk 0.53cvss 8.1epss 0.02

    npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPDAnnotHandlerUtils::create_popup_for_markup+0x12fbe via a crafted PDF document.

  • CVE-2020-10222HigMar 8, 2020
    risk 0.53cvss 8.1epss 0.02

    npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to Heap Corruption at npdf!nitro::get_property+2381 via a crafted PDF document.

  • CVE-2021-21797HigOct 18, 2021
    risk 0.52cvss 7.8epss 0.15

    An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference to a timeout object to be stored in two different places. When closed, the document will result in the reference being released…

  • CVE-2024-35288HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because custom actions occur unsafely in repair mode. CertUtil is run in a conhost.exe window, and there is a mechanism allowing CTRL+o to launch cmd.exe as NT…

  • CVE-2013-3553HigFeb 8, 2018
    risk 0.51cvss 7.8epss 0.02

    Nitro Pro 7.5.0.22 and earlier and Nitro Reader 2.5.0.36 and earlier allow remote attackers to execute arbitrary code via a crafted PDF file.

  • CVE-2013-3552HigFeb 8, 2018
    risk 0.51cvss 7.8epss 0.03

    Nitro Pro 7.5.0.29 and earlier and Nitro Reader 2.5.0.45 and earlier allow remote attackers to execute arbitrary code via a crafted PDF file.

  • CVE-2016-8713HigFeb 10, 2017
    risk 0.51cvss 7.8epss 0.01

    A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10.5.9.9. A specially crafted PDF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim a specific PDF file to…

  • CVE-2016-8711HigFeb 10, 2017
    risk 0.51cvss 7.8epss 0.02

    A potential remote code execution vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A specially crafted PDF file can cause a vulnerability resulting in potential code execution. An attacker can send the victim a specific PDF file to trigger this…

  • CVE-2016-8709HigFeb 10, 2017
    risk 0.51cvss 7.8epss 0.01

    A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A specially crafted PDF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim a specific PDF file to trigger…

  • CVE-2025-69624HigApr 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Nitro PDF Pro before 14.43 for Windows contains a NULL pointer dereference vulnerability in the JavaScript implementation of app.alert(). When app.alert() is called with more than one argument and the first argument evaluates to null (for example, app.alert(app.activeDocs, true)…

  • CVE-2025-66769HigApr 13, 2026
    risk 0.49cvss 7.5epss 0.00

    A NULL pointer dereference in Nitro PDF Pro for Windows v14.41.1.4 allows attackers to cause a Denial of Service (DoS) via a crafted XFA packet.

  • CVE-2020-6093MedMay 18, 2020
    risk 0.36cvss 5.5epss 0.03

    An exploitable information disclosure vulnerability exists in the way Nitro Pro 13.9.1.155 does XML error handling. A specially crafted PDF document can cause uninitialized memory access resulting in information disclosure. In order to trigger this vulnerability, victim must…