CVE-2019-19817
MEDIUMGonitro Nitro Free Pdf Reader - Out-of-Bounds Read
Title source: ruleDescription
The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x2e8a Out-of-Bounds Read via crafted Unicode content.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://nafiez.github.io/security/vulnerability/remote/2019/12/12/multiple-nitro-pdf-vulnerability.html
Exploit, Third Party Advisory x_refsource_misc
https://github.com/nafiez/nafiez.github.io/blob/master/_posts/2019-12-12-multiple-nitro-pdf-vulnerability.md
Scores
CVSS v3
5.5
EPSS
0.0001
EPSS Percentile
1.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Details
CWE
CWE-125
Status
published
Products (1)
gonitro/nitro_free_pdf_reader
12.0.0.112
Published
Jan 10, 2020
Tracked Since
Feb 18, 2026