Gonitro
Gonitro Nitro PRO: vulnerabilidades y CVE
Gonitro Nitro PRO tiene 18 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-21797 | Alta (7.8) | 15% | — | 18 oct 2021 | An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference to a timeout object to be stored in two different places. When… |
| CVE-2021-21796 | Alta (7.8) | 16% | — | 18 oct 2021 | An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an object containing the path to a document to be destroyed and then later… |
| CVE-2021-21798 | Alta (7.8) | 16% | — | 15 sept 2021 | An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a stack variable to go out of scope, resulting in the… |
| CVE-2018-18689 | Media (5.3) | 3.7% | — | 7 ene 2021 | The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple… |
| CVE-2018-18688 | Media (5.3) | 1.1% | — | 7 ene 2021 | The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple… |
| CVE-2020-6116 | Alta (7.8) | 28% | — | 17 sept 2020 | An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. When drawing the contents of a page using colors from an indexed colorspace, the… |
| CVE-2020-6115 | Alta (7.8) | 2.7% | — | 17 sept 2020 | An exploitable vulnerability exists in the cross-reference table repairing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. While searching for an object identifier in a malformed document that is missing… |
| CVE-2020-6113 | Alta (7.8) | 65% | — | 17 sept 2020 | An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when updating its cross-reference table. When processing an object stream from a PDF… |
| CVE-2020-6112 | Alta (7.8) | 17% | — | 17 sept 2020 | An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when decoding sub-samples. While initializing tiles with sub-sample data,… |
| CVE-2020-6146 | Alta (8.8) | 76% | — | 16 sept 2020 | An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300. When drawing the contents of a page and selecting the stroke color from an 'ICCBased'… |
| CVE-2020-6093 | Media (5.5) | 2.6% | — | 18 may 2020 | An exploitable information disclosure vulnerability exists in the way Nitro Pro 13.9.1.155 does XML error handling. A specially crafted PDF document can cause uninitialized memory access resulting in information… |
| CVE-2020-6092 | Alta (7.8) | 42% | — | 18 may 2020 | An exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects. A specially crafted PDF file can trigger an integer overflow that can lead to arbitrary code execution. In order… |
| CVE-2020-6074 | Alta (8.8) | 41% | — | 18 may 2020 | An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF document can cause a use-after-free which can lead to remote code execution. An attacker can provide… |
| CVE-2020-10223 | Alta (8.1) | 2.5% | — | 8 mar 2020 | npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPDAnnotHandlerUtils::create_popup_for_markup+0x12fbe via a crafted PDF document. |
| CVE-2020-10222 | Alta (8.1) | 2.5% | — | 8 mar 2020 | npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to Heap Corruption at npdf!nitro::get_property+2381 via a crafted PDF document. |
| CVE-2019-18958 | Alta (7.8) | 0.55% | — | 21 nov 2019 | Nitro Pro before 13.2 creates a debug.log file in the directory where a .pdf file is located, if the .pdf document was produced by an OCR operation on the JPEG output of a scanner. Reportedly, this can have a security… |
| CVE-2017-7442 | Alta (8.8) | 41% | — | 3 ago 2017 | Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences. |
| CVE-2017-7950 | Media (5.5) | 2.5% | — | 7 jul 2017 | Nitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX file. |