Nitro Pro
Vendor:
First CVE: Jul 7, 2017 · Active for 9 years
18
Total CVEs
More Total CVEs than 93% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Nitro Pro over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 7, 2017
9 years ago
Most Recent CVE
Oct 18, 2021
1,741 days ago
CVE Severity & Scoring
Nitro Pro18 CVEs
22%
78%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local11 (61.1%)
Network7 (38.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (16.7%)
Unknown0 (0.0%)
Required15 (83.3%)
Privileges Required
Low1 (5.6%)
High0 (0.0%)
None17 (94.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7442HIGH Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences. | Aug 3, 2017 | 8.8 | 71 | NO | YES |
CVE-2020-6146HIGH An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300. When drawing the contents of a page and selecting the st | Sep 16, 2020 | 8.8 | 63 | NO | NO |
CVE-2020-6113HIGH An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when updating its cross-reference table. When process | Sep 17, 2020 | 7.8 | 56 | NO | NO |
CVE-2020-6074HIGH An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF document can cause a use-after-free which can lead to remote c | May 18, 2020 | 8.8 | 42 | NO | NO |
CVE-2020-6092HIGH An exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects. A specially crafted PDF file can trigger an integer overflow that can lea | May 18, 2020 | 7.8 | 40 | NO | NO |
CVE-2021-21797HIGH An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference to a timeout object to be stor | Oct 18, 2021 | 7.8 | 32 | NO | NO |
CVE-2021-21796HIGH An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an object containing the path to a docu | Oct 18, 2021 | 7.8 | 32 | NO | NO |
CVE-2021-21798HIGH An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a stack variable to g | Sep 15, 2021 | 7.8 | 32 | NO | NO |
CVE-2020-6116HIGH An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. When drawing the contents of a page using colors fr | Sep 17, 2020 | 7.8 | 32 | NO | NO |
CVE-2017-7950MEDIUM Nitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX file. | Jul 7, 2017 | 5.5 | 30 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
5.6% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
11.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Nitro Pro
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 13.9.1.155 | 3 | 7.4 | 28.6% | 0 | 0 |
| 13.33.2.645 | 3 | 7.8 | 15.6% | 0 | 0 |
| 13.31.0.605 | 3 | 7.8 | 15.6% | 0 | 0 |
| 13.16.2.300 | 5 | 8.0 | 38.8% | 0 | 0 |
| 13.13.2.242 | 5 | 8.0 | 38.8% | 0 | 0 |
| 11.0.3.173 | 3 | 6.5 | 15.2% | 0 | 1 |