Gonitro maintains a narrowly focused portfolio of PDF creation, editing, and viewing applications—Nitro Pro, Nitro PDF Pro, Nitro Reader, and related products—that serve both enterprise and consumer audiences. Despite the modest product count, the vendor's presence in the vulnerability landscape reflects the widespread deployment of these applications and the complexity of PDF parsing and rendering. The recurring weakness classes affecting this vendor—out-of-bounds writes, use-after-free conditions, heap-based buffer overflows, integer overflows, and NULL pointer dereferences—are characteristic of memory-safety challenges in native PDF processing engines. Public exploit code has emerged for several of this vendor's vulnerabilities, underscoring the appeal of PDF readers as attack vectors for document-based exploitation. Defenders should monitor Gonitro's updates for its PDF products and prioritize patching where these applications handle untrusted documents; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gonitro over time
Signals from CVEs in this vendor scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7442HIGH Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences. | Aug 3, 2017 | 8.8 | 71 | NO | YES |
CVE-2020-6146HIGH An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300. When drawing the contents of a page and selecting the st | Sep 16, 2020 | 8.8 | 63 | NO | NO |
CVE-2020-6113HIGH An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when updating its cross-reference table. When process | Sep 17, 2020 | 7.8 | 56 | NO | NO |
CVE-2020-6074HIGH An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF document can cause a use-after-free which can lead to remote c | May 18, 2020 | 8.8 | 42 | NO | NO |
CVE-2020-6092HIGH An exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects. A specially crafted PDF file can trigger an integer overflow that can lea | May 18, 2020 | 7.8 | 40 | NO | NO |
CVE-2021-21797HIGH An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference to a timeout object to be stor | Oct 18, 2021 | 7.8 | 32 | NO | NO |
CVE-2021-21796HIGH An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an object containing the path to a docu | Oct 18, 2021 | 7.8 | 32 | NO | NO |
CVE-2021-21798HIGH An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a stack variable to g | Sep 15, 2021 | 7.8 | 32 | NO | NO |
CVE-2020-6116HIGH An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. When drawing the contents of a page using colors fr | Sep 17, 2020 | 7.8 | 32 | NO | NO |
CVE-2017-7950MEDIUM Nitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX file. | Jul 7, 2017 | 5.5 | 30 | NO | YES |
Signals from CVEs in this vendor scope (35 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gonitro.
Media articles that mention a CVE ID that affects a product developed by Gonitro — matched by CVE ID, not by vendor name.