CVE-2025-66769
- EPSS 0%
- Veröffentlicht 13.04.2026 00:00:00
- Zuletzt bearbeitet 23.04.2026 16:51:39
A NULL pointer dereference in Nitro PDF Pro for Windows v14.41.1.4 allows attackers to cause a Denial of Service (DoS) via a crafted XFA packet.
CVE-2025-69624
- EPSS 0%
- Veröffentlicht 13.04.2026 00:00:00
- Zuletzt bearbeitet 23.04.2026 16:51:04
Nitro PDF Pro for Windows 14.41.1.4 contains a NULL pointer dereference vulnerability in the JavaScript implementation of app.alert(). When app.alert() is called with more than one argument and the first argument evaluates to null (for example, app.a...
CVE-2025-69627
- EPSS 0%
- Veröffentlicht 13.04.2026 00:00:00
- Zuletzt bearbeitet 23.04.2026 13:33:42
Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript method this.mailDoc(). During execution, an internal XID object is allocated and then freed prematurely, after which the freed po...
CVE-2025-67825
- EPSS 0%
- Veröffentlicht 08.01.2026 00:00:00
- Zuletzt bearbeitet 02.02.2026 17:16:16
An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information from a non-verified PDF field rather than from the verified certificate subject. This could allow a document to present inconsist...
CVE-2024-35288
- EPSS 0.26%
- Veröffentlicht 09.10.2024 04:15:08
- Zuletzt bearbeitet 15.04.2026 00:35:42
Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because custom actions occur unsafely in repair mode. CertUtil is run in a conhost.exe window, and there is a mechanism allowing CTRL+o t...
CVE-2016-8709
- EPSS 0.02%
- Veröffentlicht 10.02.2017 17:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A specially crafted PDF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim a ...
CVE-2016-8711
- EPSS 0.04%
- Veröffentlicht 10.02.2017 17:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A potential remote code execution vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A specially crafted PDF file can cause a vulnerability resulting in potential code execution. An attacker can send the victim a specific PDF file...
CVE-2016-8713
- EPSS 0.02%
- Veröffentlicht 10.02.2017 17:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10.5.9.9. A specially crafted PDF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the vic...