CVE-2019-5050

HIGH

NitroPDF 12.12.1.522 - Memory Corruption

Title source: llm
STIX 2.1

Description

A specifically crafted PDF file can lead to a heap corruption when opened in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would need to open the malicious file.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0819

Scores

CVSS v3 7.8
EPSS 0.0015
EPSS Percentile 35.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-122 CWE-787
Status published
Products (1)
gonitro/nitropdf 12.12.1.522
Published Oct 09, 2019
Tracked Since Feb 18, 2026