VYPR

Vendor CVEs

Gonitro

All CVEs

35 total · sorted by risk
  • CVE-2020-6146HigSep 16, 2020
    risk 0.63cvss 8.8epss 0.77

    An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300. When drawing the contents of a page and selecting the stroke color from an 'ICCBased' colorspace, the application will read a length from the file and use…

  • CVE-2017-7442HigAug 3, 2017
    risk 0.63cvss 8.8epss 0.41

    Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.

  • CVE-2020-6074HigMay 18, 2020
    risk 0.60cvss 8.8epss 0.41

    An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF document can cause a use-after-free which can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2020-6113HigSep 17, 2020
    risk 0.56cvss 7.8epss 0.69

    An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when updating its cross-reference table. When processing an object stream from a PDF document, the application will perform a calculation in order to…

  • CVE-2025-69627HigApr 13, 2026
    risk 0.55cvss 8.4epss 0.00

    Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript method this.mailDoc(). During execution, an internal XID object is allocated and then freed prematurely, after which the freed pointer is still passed into UI…

  • CVE-2020-6092HigMay 18, 2020
    risk 0.54cvss 7.8epss 0.42

    An exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects. A specially crafted PDF file can trigger an integer overflow that can lead to arbitrary code execution. In order to trigger this vulnerability, victim must open a malicious…

  • CVE-2020-6116HigSep 17, 2020
    risk 0.53cvss 7.8epss 0.28

    An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. When drawing the contents of a page using colors from an indexed colorspace, the application can miscalculate the size of a buffer when allocating…

  • CVE-2020-10223HigMar 8, 2020
    risk 0.53cvss 8.1epss 0.02

    npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPDAnnotHandlerUtils::create_popup_for_markup+0x12fbe via a crafted PDF document.

  • CVE-2020-10222HigMar 8, 2020
    risk 0.53cvss 8.1epss 0.02

    npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to Heap Corruption at npdf!nitro::get_property+2381 via a crafted PDF document.

  • CVE-2021-21797HigOct 18, 2021
    risk 0.52cvss 7.8epss 0.15

    An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference to a timeout object to be stored in two different places. When closed, the document will result in the reference being released…

  • CVE-2021-21796HigOct 18, 2021
    risk 0.52cvss 7.8epss 0.16

    An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an object containing the path to a document to be destroyed and then later reused, resulting in a use-after-free vulnerability, which can…

  • CVE-2021-21798HigSep 15, 2021
    risk 0.52cvss 7.8epss 0.16

    An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a stack variable to go out of scope, resulting in the application dereferencing a stale pointer. This can lead to code…

  • CVE-2020-6112HigSep 17, 2020
    risk 0.52cvss 7.8epss 0.17

    An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when decoding sub-samples. While initializing tiles with sub-sample data, the application can miscalculate a pointer for the stripes…

  • CVE-2020-6115HigSep 17, 2020
    risk 0.51cvss 7.8epss 0.03

    An exploitable vulnerability exists in the cross-reference table repairing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. While searching for an object identifier in a malformed document that is missing from the cross-reference table, the application will save…

  • CVE-2013-2773HigJan 14, 2020
    risk 0.51cvss 7.8epss 0.00

    Nitro PDF 8.5.0.26: A specially crafted DLL file can facilitate Arbitrary Code Execution

  • CVE-2019-18958HigNov 21, 2019
    risk 0.51cvss 7.8epss 0.01

    Nitro Pro before 13.2 creates a debug.log file in the directory where a .pdf file is located, if the .pdf document was produced by an OCR operation on the JPEG output of a scanner. Reportedly, this can have a security risk if debug.log is later edited and then executed.

  • CVE-2019-5053HigOct 9, 2019
    risk 0.51cvss 7.8epss 0.01

    An exploitable use-after-free vulnerability exists in the Length parsing function of NitroPDF. A specially crafted PDF can cause a type confusion, resulting in a use-after-free condition. An attacker can craft a malicious PDF to trigger this vulnerability.

  • CVE-2019-5050HigOct 9, 2019
    risk 0.51cvss 7.8epss 0.03

    A specifically crafted PDF file can lead to a heap corruption when opened in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would need to open the malicious file.

  • CVE-2019-5048HigOct 9, 2019
    risk 0.51cvss 7.8epss 0.02

    A specifically crafted PDF file can lead to a heap corruption when opened in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would need to open the malicious file.

  • CVE-2019-5047HigOct 9, 2019
    risk 0.51cvss 7.8epss 0.01

    An exploitable Use After Free vulnerability exists in the CharProcs parsing functionality of NitroPDF. A specially crafted PDF can cause a type confusion, resulting in a Use After Free. An attacker can craft a malicious PDF to trigger this vulnerability.

  • CVE-2019-5046HigOct 9, 2019
    risk 0.51cvss 7.8epss 0.02

    A specifically crafted jpeg2000 file embedded in a PDF file can lead to a heap corruption when opening a PDF document in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would…

  • CVE-2019-5045HigOct 9, 2019
    risk 0.51cvss 7.8epss 0.02

    A specifically crafted jpeg2000 file embedded in a PDF file can lead to a heap corruption when opening a PDF document in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would…

  • CVE-2016-8713HigFeb 10, 2017
    risk 0.51cvss 7.8epss 0.01

    A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10.5.9.9. A specially crafted PDF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim a specific PDF file to…

  • CVE-2016-8711HigFeb 10, 2017
    risk 0.51cvss 7.8epss 0.02

    A potential remote code execution vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A specially crafted PDF file can cause a vulnerability resulting in potential code execution. An attacker can send the victim a specific PDF file to trigger this…

  • CVE-2016-8709HigFeb 10, 2017
    risk 0.51cvss 7.8epss 0.01

    A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A specially crafted PDF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim a specific PDF file to trigger…

  • CVE-2025-69624HigApr 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Nitro PDF Pro before 14.43 for Windows contains a NULL pointer dereference vulnerability in the JavaScript implementation of app.alert(). When app.alert() is called with more than one argument and the first argument evaluates to null (for example, app.alert(app.activeDocs, true)…

  • CVE-2025-66769HigApr 13, 2026
    risk 0.49cvss 7.5epss 0.00

    A NULL pointer dereference in Nitro PDF Pro for Windows v14.41.1.4 allows attackers to cause a Denial of Service (DoS) via a crafted XFA packet.

  • CVE-2017-7950MedJul 7, 2017
    risk 0.39cvss 5.5epss 0.02

    Nitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX file.

  • CVE-2025-67825MedJan 8, 2026
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information from a non-verified PDF field rather than from the verified certificate subject. This could allow a document to present inconsistent signer details. The…

  • CVE-2020-6093MedMay 18, 2020
    risk 0.36cvss 5.5epss 0.03

    An exploitable information disclosure vulnerability exists in the way Nitro Pro 13.9.1.155 does XML error handling. A specially crafted PDF document can cause uninitialized memory access resulting in information disclosure. In order to trigger this vulnerability, victim must…

  • CVE-2019-19819MedJan 10, 2020
    risk 0.36cvss 5.5epss 0.01

    The JBIG2Globals library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x90ec NULL Pointer Dereference via crafted Unicode content.

  • CVE-2019-19817MedJan 10, 2020
    risk 0.36cvss 5.5epss 0.01

    The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x2e8a Out-of-Bounds Read via crafted Unicode content.

  • CVE-2019-19818MedDec 16, 2019
    risk 0.36cvss 5.5epss 0.01

    The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0xa08a Out-of-Bounds Read via crafted Unicode content.

  • CVE-2018-18689MedJan 7, 2021
    risk 0.35cvss 5.3epss 0.04

    The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations…

  • CVE-2018-18688MedJan 7, 2021
    risk 0.35cvss 5.3epss 0.01

    The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature…