Gonitro

Nitro Pro

18 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 71.71%
  • Published 18.10.2021 13:15:09
  • Last modified 21.11.2024 05:48:59

An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference to a timeout object to be stored in two different places. When closed, the document will result in t...

Exploit
  • EPSS 75.47%
  • Published 18.10.2021 13:15:09
  • Last modified 21.11.2024 05:48:59

An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an object containing the path to a document to be destroyed and then later reused, resulting in a use-after-f...

Exploit
  • EPSS 40.26%
  • Published 15.09.2021 14:15:08
  • Last modified 21.11.2024 05:48:59

An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a stack variable to go out of scope, resulting in the application dereferencing a stale poi...

  • EPSS 0.01%
  • Published 07.01.2021 18:15:12
  • Last modified 27.11.2024 20:11:45

The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteR...

  • EPSS 0%
  • Published 07.01.2021 18:15:12
  • Last modified 21.11.2024 03:56:22

The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the...

Exploit
  • EPSS 0.29%
  • Published 17.09.2020 13:15:16
  • Last modified 21.11.2024 05:35:08

An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. When drawing the contents of a page using colors from an indexed colorspace, the application can miscalculate the size of...

Exploit
  • EPSS 0.01%
  • Published 17.09.2020 13:15:16
  • Last modified 21.11.2024 05:35:08

An exploitable vulnerability exists in the cross-reference table repairing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. While searching for an object identifier in a malformed document that is missing from the cross-reference table,...

Exploit
  • EPSS 0.5%
  • Published 17.09.2020 13:15:16
  • Last modified 21.11.2024 05:35:08

An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when updating its cross-reference table. When processing an object stream from a PDF document, the application will perform...

Exploit
  • EPSS 0.05%
  • Published 17.09.2020 13:15:15
  • Last modified 21.11.2024 05:35:07

An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when decoding sub-samples. While initializing tiles with sub-sample data, the application can miscalculat...

Exploit
  • EPSS 0.5%
  • Published 16.09.2020 19:15:14
  • Last modified 21.11.2024 05:35:11

An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300. When drawing the contents of a page and selecting the stroke color from an 'ICCBased' colorspace, the application will read a ...