Gonitro

Nitro Pro

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 71.71%
  • Veröffentlicht 18.10.2021 13:15:09
  • Zuletzt bearbeitet 21.11.2024 05:48:59

An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference to a timeout object to be stored in two different places. When closed, the document will result in t...

Exploit
  • EPSS 75.47%
  • Veröffentlicht 18.10.2021 13:15:09
  • Zuletzt bearbeitet 21.11.2024 05:48:59

An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an object containing the path to a document to be destroyed and then later reused, resulting in a use-after-f...

Exploit
  • EPSS 40.26%
  • Veröffentlicht 15.09.2021 14:15:08
  • Zuletzt bearbeitet 21.11.2024 05:48:59

An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a stack variable to go out of scope, resulting in the application dereferencing a stale poi...

  • EPSS 0.01%
  • Veröffentlicht 07.01.2021 18:15:12
  • Zuletzt bearbeitet 27.11.2024 20:11:45

The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteR...

  • EPSS 0%
  • Veröffentlicht 07.01.2021 18:15:12
  • Zuletzt bearbeitet 21.11.2024 03:56:22

The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 17.09.2020 13:15:16
  • Zuletzt bearbeitet 21.11.2024 05:35:08

An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. When drawing the contents of a page using colors from an indexed colorspace, the application can miscalculate the size of...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 17.09.2020 13:15:16
  • Zuletzt bearbeitet 21.11.2024 05:35:08

An exploitable vulnerability exists in the cross-reference table repairing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. While searching for an object identifier in a malformed document that is missing from the cross-reference table,...

Exploit
  • EPSS 0.5%
  • Veröffentlicht 17.09.2020 13:15:16
  • Zuletzt bearbeitet 21.11.2024 05:35:08

An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when updating its cross-reference table. When processing an object stream from a PDF document, the application will perform...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 17.09.2020 13:15:15
  • Zuletzt bearbeitet 21.11.2024 05:35:07

An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when decoding sub-samples. While initializing tiles with sub-sample data, the application can miscalculat...

Exploit
  • EPSS 0.5%
  • Veröffentlicht 16.09.2020 19:15:14
  • Zuletzt bearbeitet 21.11.2024 05:35:11

An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300. When drawing the contents of a page and selecting the stroke color from an 'ICCBased' colorspace, the application will read a ...