Description
The JBIG2Globals library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x90ec NULL Pointer Dereference via crafted Unicode content.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://nafiez.github.io/security/vulnerability/remote/2019/12/12/multiple-nitro-pdf-vulnerability.html
Exploit, Third Party Advisory x_refsource_misc
https://github.com/nafiez/nafiez.github.io/blob/master/_posts/2019-12-12-multiple-nitro-pdf-vulnerability.md
Scores
CVSS v3
5.5
EPSS
0.0101
EPSS Percentile
58.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Details
CWE
CWE-476
Status
published
Products (1)
gonitro/nitropdf
12.0.0.112
Published
Jan 10, 2020
Tracked Since
Feb 18, 2026