Gonitro

Nitro Pro

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.01%
  • Veröffentlicht 18.05.2020 17:15:10
  • Zuletzt bearbeitet 21.11.2024 05:35:04

An exploitable information disclosure vulnerability exists in the way Nitro Pro 13.9.1.155 does XML error handling. A specially crafted PDF document can cause uninitialized memory access resulting in information disclosure. In order to trigger this v...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 18.05.2020 17:15:10
  • Zuletzt bearbeitet 21.11.2024 05:35:04

An exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects. A specially crafted PDF file can trigger an integer overflow that can lead to arbitrary code execution. In order to trigger this vulnerability,...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 18.05.2020 17:15:10
  • Zuletzt bearbeitet 21.11.2024 05:35:02

An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF document can cause a use-after-free which can lead to remote code execution. An attacker can provide a malicious file to trigger thi...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 08.03.2020 23:15:11
  • Zuletzt bearbeitet 21.11.2024 04:54:59

npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPDAnnotHandlerUtils::create_popup_for_markup+0x12fbe via a crafted PDF document.

Exploit
  • EPSS 0.02%
  • Veröffentlicht 08.03.2020 23:15:10
  • Zuletzt bearbeitet 21.11.2024 04:54:59

npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to Heap Corruption at npdf!nitro::get_property+2381 via a crafted PDF document.

Exploit
  • EPSS 0.01%
  • Veröffentlicht 21.11.2019 15:15:14
  • Zuletzt bearbeitet 21.11.2024 04:33:54

Nitro Pro before 13.2 creates a debug.log file in the directory where a .pdf file is located, if the .pdf document was produced by an OCR operation on the JPEG output of a scanner. Reportedly, this can have a security risk if debug.log is later edite...

Exploit
  • EPSS 68.98%
  • Veröffentlicht 03.08.2017 08:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.

  • EPSS 0.09%
  • Veröffentlicht 07.07.2017 11:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Nitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX file.