Nitro Pro

Vendor:

First CVE: Jul 7, 2017 · Active for 9 years

18
Total CVEs
More Total CVEs than 93% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Nitro Pro over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 7, 2017
9 years ago
Most Recent CVE
Oct 18, 2021
1,741 days ago

CVE Severity & Scoring

Nitro Pro18 CVEs
All CVEs352,708 CVEs
MediumHigh
Attack Vector
Local11 (61.1%)
Network7 (38.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (16.7%)
Unknown0 (0.0%)
Required15 (83.3%)
Privileges Required
Low1 (5.6%)
High0 (0.0%)
None17 (94.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.
Aug 3, 20178.871NOYES
An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300. When drawing the contents of a page and selecting the st
Sep 16, 20208.863NONO
An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when updating its cross-reference table. When process
Sep 17, 20207.856NONO
An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF document can cause a use-after-free which can lead to remote c
May 18, 20208.842NONO
An exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects. A specially crafted PDF file can trigger an integer overflow that can lea
May 18, 20207.840NONO
An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference to a timeout object to be stor
Oct 18, 20217.832NONO
An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an object containing the path to a docu
Oct 18, 20217.832NONO
An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a stack variable to g
Sep 15, 20217.832NONO
An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. When drawing the contents of a page using colors fr
Sep 17, 20207.832NONO
Nitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX file.
Jul 7, 20175.530NOYES

Exploit Exposure

Signals from CVEs in this product scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
5.6% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
11.1% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (18 CVEs).

Media Mentions

Signals from CVEs in this product scope (18 CVEs).

Top CNAs Publishing CVEs For Nitro Pro

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
13.9.1.15537.428.6%00
13.33.2.64537.815.6%00
13.31.0.60537.815.6%00
13.16.2.30058.038.8%00
13.13.2.24258.038.8%00
11.0.3.17336.515.2%01