Show filters
31 Total Results
Displaying 11-20 of 31
Sort by:
Attacker Value
Unknown

CVE-2020-6074

Disclosure Date: May 18, 2020 (last updated February 21, 2025)
An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF document can cause a use-after-free which can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.
Attacker Value
Unknown

CVE-2020-6092

Disclosure Date: May 18, 2020 (last updated February 21, 2025)
An exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects. A specially crafted PDF file can trigger an integer overflow that can lead to arbitrary code execution. In order to trigger this vulnerability, victim must open a malicious file.
Attacker Value
Unknown

CVE-2020-6093

Disclosure Date: May 18, 2020 (last updated February 21, 2025)
An exploitable information disclosure vulnerability exists in the way Nitro Pro 13.9.1.155 does XML error handling. A specially crafted PDF document can cause uninitialized memory access resulting in information disclosure. In order to trigger this vulnerability, victim must open a malicious file.
Attacker Value
Unknown

CVE-2020-10222

Disclosure Date: March 08, 2020 (last updated November 27, 2024)
npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to Heap Corruption at npdf!nitro::get_property+2381 via a crafted PDF document.
Attacker Value
Unknown

CVE-2020-10223

Disclosure Date: March 08, 2020 (last updated February 21, 2025)
npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPDAnnotHandlerUtils::create_popup_for_markup+0x12fbe via a crafted PDF document.
Attacker Value
Unknown

CVE-2013-2773

Disclosure Date: January 14, 2020 (last updated February 21, 2025)
Nitro PDF 8.5.0.26: A specially crafted DLL file can facilitate Arbitrary Code Execution
Attacker Value
Unknown

CVE-2019-19817

Disclosure Date: January 10, 2020 (last updated February 21, 2025)
The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x2e8a Out-of-Bounds Read via crafted Unicode content.
Attacker Value
Unknown

CVE-2019-19818

Disclosure Date: December 16, 2019 (last updated November 27, 2024)
The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0xa08a Out-of-Bounds Read via crafted Unicode content.
Attacker Value
Unknown

CVE-2019-18958

Disclosure Date: November 21, 2019 (last updated November 27, 2024)
Nitro Pro before 13.2 creates a debug.log file in the directory where a .pdf file is located, if the .pdf document was produced by an OCR operation on the JPEG output of a scanner. Reportedly, this can have a security risk if debug.log is later edited and then executed.
Attacker Value
Unknown

CVE-2019-19819

Disclosure Date: November 05, 2019 (last updated February 21, 2025)
The JBIG2Globals library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x90ec NULL Pointer Dereference via crafted Unicode content.