Записи gonitro
36 опубликованных записей вендора gonitro.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 2,8 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-416 Use After Free6
- CWE-122 Heap-based Buffer Overflow5
- CWE-787 Out-of-bounds Write3
- CWE-476 NULL Pointer Dereference3
- CWE-190 Integer Overflow or Wraparound2
- CWE-347 Improper Verification of Cryptographic Signature2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
36 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
58В плане | CVE-2020-6146Эксплойта нет | An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300.gonitro · nitro pro · CWE-122 | Высокая8,8 | — | 76,1 % | 16 сент. 2020 г. |
51В плане | CVE-2020-6113Эксплойта нет | An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when updatinggonitro · nitro pro · CWE-190 | Высокая7,8 | — | 65,0 % | 17 сент. 2020 г. |
47В плане | CVE-2020-6074Эксплойта нет | An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155.gonitro · nitro pro · CWE-416 | Высокая8,8 | — | 40,9 % | 18 мая 2020 г. |
47В плане | CVE-2017-7442Готовый эксплойт | Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.gonitro · nitro pro · CWE-22 | Высокая8,8 | — | 40,7 % | 3 авг. 2017 г. |
44В плане | CVE-2020-6092Эксплойта нет | An exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects.gonitro · nitro pro · CWE-190 | Высокая7,8 | — | 42,3 % | 18 мая 2020 г. |
40В плане | CVE-2020-6116Эксплойта нет | An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242.gonitro · nitro pro · CWE-680 | Высокая7,8 | — | 28,4 % | 17 сент. 2020 г. |
36Наблюдать | CVE-2020-6112Эксплойта нет | An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2gonitro · nitro pro · CWE-823 | Высокая7,8 | — | 17,1 % | 17 сент. 2020 г. |
36Наблюдать | CVE-2021-21798Эксплойта нет | An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF.gonitro · nitro pro · CWE-562 | Высокая7,8 | — | 16,0 % | 15 сент. 2021 г. |
36Наблюдать | CVE-2021-21796Эксплойта нет | An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF.gonitro · nitro pro · CWE-416 | Высокая7,8 | — | 15,8 % | 18 окт. 2021 г. |
36Наблюдать | CVE-2021-21797Эксплойта нет | An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF.gonitro · nitro pro · CWE-415 | Высокая7,8 | — | 15,0 % | 18 окт. 2021 г. |
33Наблюдать | CVE-2020-10223Эксплойта нет | npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPDAnnotHandlerUtils::cgonitro · nitro pro · CWE-787 | Высокая8,1 | — | 2,5 % | 8 мар. 2020 г. |
33Наблюдать | CVE-2020-10222Эксплойта нет | npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to Heap Corruption at npdf!nitro::get_property+2381 via a crafted PDF document.gonitro · nitro pro | Высокая8,1 | — | 2,5 % | 8 мар. 2020 г. |
33Наблюдать | CVE-2025-69627Эксплойта нет | Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript method this.mailDocgonitro · nitro pdf pro · CWE-416 | Высокая8,4 | — | 0,2 % | 13 апр. 2026 г. |
32Наблюдать | CVE-2020-6115Эксплойта нет | An exploitable vulnerability exists in the cross-reference table repairing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242.gonitro · nitro pro · CWE-416 | Высокая7,8 | — | 2,7 % | 17 сент. 2020 г. |
32Наблюдать | CVE-2019-5050Эксплойта нет | A specifically crafted PDF file can lead to a heap corruption when opened in NitroPDF 12.12.1.522.gonitro · nitropdf · CWE-122 | Высокая7,8 | — | 2,6 % | 9 окт. 2019 г. |
32Наблюдать | CVE-2019-5045Эксплойта нет | A specifically crafted jpeg2000 file embedded in a PDF file can lead to a heap corruption when opening a PDF document in NitroPDF 12.12.1.52gonitro · nitropdf · CWE-122 | Высокая7,8 | — | 2,3 % | 9 окт. 2019 г. |
32Наблюдать | CVE-2019-5048Эксплойта нет | A specifically crafted PDF file can lead to a heap corruption when opened in NitroPDF 12.12.1.522.gonitro · nitropdf · CWE-122 | Высокая7,8 | — | 2,3 % | 9 окт. 2019 г. |
32Наблюдать | CVE-2019-5046Эксплойта нет | A specifically crafted jpeg2000 file embedded in a PDF file can lead to a heap corruption when opening a PDF document in NitroPDF 12.12.1.52gonitro · nitropdf · CWE-122 | Высокая7,8 | — | 2,3 % | 9 окт. 2019 г. |
32Наблюдать | CVE-2016-8711Эксплойта нет | A potential remote code execution vulnerability exists in the PDF parsing functionality of Nitro Pro 10.gonitro · nitro pdf pro | Высокая7,8 | — | 2,0 % | 10 февр. 2017 г. |
31Наблюдать | CVE-2019-5047Эксплойта нет | An exploitable Use After Free vulnerability exists in the CharProcs parsing functionality of NitroPDF.gonitro · nitropdf · CWE-416 | Высокая7,8 | — | 1,3 % | 9 окт. 2019 г. |
31Наблюдать | CVE-2019-5053Эксплойта нет | An exploitable use-after-free vulnerability exists in the Length parsing function of NitroPDF.gonitro · nitropdf · CWE-416 | Высокая7,8 | — | 1,3 % | 9 окт. 2019 г. |
31Наблюдать | CVE-2016-8709Эксплойта нет | A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10.gonitro · nitro pdf pro · CWE-787 | Высокая7,8 | — | 1,3 % | 10 февр. 2017 г. |
31Наблюдать | CVE-2016-8713Эксплойта нет | A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10.5.9.9.gonitro · nitro pdf pro · CWE-787 | Высокая7,8 | — | 1,1 % | 10 февр. 2017 г. |
31Наблюдать | CVE-2019-18958Эксплойта нет | Nitro Pro before 13.2 creates a debug.log file in the directory where a .pdf file is located, if the .pdf document was produced by an OCR opgonitro · nitro pro · CWE-732 | Высокая7,8 | — | 0,5 % | 21 нояб. 2019 г. |
31Наблюдать | CVE-2013-2773Эксплойта нет | Nitro PDF 8.5.0.26: A specially crafted DLL file can facilitate Arbitrary Code Executiongonitro · nitropdf · CWE-426 | Высокая7,8 | — | 0,4 % | 14 янв. 2020 г. |
- CVE-2020-614658В плане
An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300.
ВысокаяCVSS 8,8Эксплойта нетEPSS 76 %gonitro · nitro pro16 сент. 2020 г.
- CVE-2020-611351В плане
An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when updating
ВысокаяCVSS 7,8Эксплойта нетEPSS 65 %gonitro · nitro pro17 сент. 2020 г.
- CVE-2020-607447В плане
An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155.
ВысокаяCVSS 8,8Эксплойта нетEPSS 41 %gonitro · nitro pro18 мая 2020 г.
- CVE-2017-744247В плане
Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.
ВысокаяCVSS 8,8Готовый эксплойтEPSS 41 %gonitro · nitro pro3 авг. 2017 г.
- CVE-2020-609244В плане
An exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects.
ВысокаяCVSS 7,8Эксплойта нетEPSS 42 %gonitro · nitro pro18 мая 2020 г.
- CVE-2020-611640В плане
An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242.
ВысокаяCVSS 7,8Эксплойта нетEPSS 28 %gonitro · nitro pro17 сент. 2020 г.
- CVE-2020-611236Наблюдать
An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2
ВысокаяCVSS 7,8Эксплойта нетEPSS 17 %gonitro · nitro pro17 сент. 2020 г.
- CVE-2021-2179836Наблюдать
An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF.
ВысокаяCVSS 7,8Эксплойта нетEPSS 16 %gonitro · nitro pro15 сент. 2021 г.
- CVE-2021-2179636Наблюдать
An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF.
ВысокаяCVSS 7,8Эксплойта нетEPSS 16 %gonitro · nitro pro18 окт. 2021 г.
- CVE-2021-2179736Наблюдать
An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF.
ВысокаяCVSS 7,8Эксплойта нетEPSS 15 %gonitro · nitro pro18 окт. 2021 г.
- CVE-2020-1022333Наблюдать
npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPDAnnotHandlerUtils::c
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %gonitro · nitro pro8 мар. 2020 г.
- CVE-2020-1022233Наблюдать
npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to Heap Corruption at npdf!nitro::get_property+2381 via a crafted PDF document.
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %gonitro · nitro pro8 мар. 2020 г.
- CVE-2025-6962733Наблюдать
Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript method this.mailDoc
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %gonitro · nitro pdf pro13 апр. 2026 г.
- CVE-2020-611532Наблюдать
An exploitable vulnerability exists in the cross-reference table repairing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242.
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %gonitro · nitro pro17 сент. 2020 г.
- CVE-2019-505032Наблюдать
A specifically crafted PDF file can lead to a heap corruption when opened in NitroPDF 12.12.1.522.
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %gonitro · nitropdf9 окт. 2019 г.
- CVE-2019-504532Наблюдать
A specifically crafted jpeg2000 file embedded in a PDF file can lead to a heap corruption when opening a PDF document in NitroPDF 12.12.1.52
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %gonitro · nitropdf9 окт. 2019 г.
- CVE-2019-504832Наблюдать
A specifically crafted PDF file can lead to a heap corruption when opened in NitroPDF 12.12.1.522.
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %gonitro · nitropdf9 окт. 2019 г.
- CVE-2019-504632Наблюдать
A specifically crafted jpeg2000 file embedded in a PDF file can lead to a heap corruption when opening a PDF document in NitroPDF 12.12.1.52
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %gonitro · nitropdf9 окт. 2019 г.
- CVE-2016-871132Наблюдать
A potential remote code execution vulnerability exists in the PDF parsing functionality of Nitro Pro 10.
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %gonitro · nitro pdf pro10 февр. 2017 г.
- CVE-2019-504731Наблюдать
An exploitable Use After Free vulnerability exists in the CharProcs parsing functionality of NitroPDF.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %gonitro · nitropdf9 окт. 2019 г.
- CVE-2019-505331Наблюдать
An exploitable use-after-free vulnerability exists in the Length parsing function of NitroPDF.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %gonitro · nitropdf9 окт. 2019 г.
- CVE-2016-870931Наблюдать
A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %gonitro · nitro pdf pro10 февр. 2017 г.
- CVE-2016-871331Наблюдать
A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10.5.9.9.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %gonitro · nitro pdf pro10 февр. 2017 г.
- CVE-2019-1895831Наблюдать
Nitro Pro before 13.2 creates a debug.log file in the directory where a .pdf file is located, if the .pdf document was produced by an OCR op
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %gonitro · nitro pro21 нояб. 2019 г.
- CVE-2013-277331Наблюдать
Nitro PDF 8.5.0.26: A specially crafted DLL file can facilitate Arbitrary Code Execution
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %gonitro · nitropdf14 янв. 2020 г.