CVE-2019-19818

MEDIUM

Gonitro Nitro Free Pdf Reader - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0xa08a Out-of-Bounds Read via crafted Unicode content.

Scores

CVSS v3 5.5
EPSS 0.0001
EPSS Percentile 1.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-125
Status published
Products (1)
gonitro/nitro_free_pdf_reader 12.0.0.112
Published Dec 16, 2019
Tracked Since Feb 18, 2026