PatchSiren

Gonitro CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Gonitro CVE published 2026-04-13

CVE-2025-69627

CVE-2025-69627 is a heap use-after-free vulnerability in Nitro PDF Pro for Windows 14.41.1.4. The vulnerability occurs in the implementation of the JavaScript method this.mailDoc(). An internal XID object is allocated and then freed prematurely, after which the freed pointer is still passed into UI and logging helper functions. This can result in access violations and non-deterministic crashes. Users of N [truncated]

HIGH Gonitro CVE published 2017-02-10

CVE-2016-8713

CVE-2016-8713 is a high-severity PDF parsing memory corruption issue in Nitro Pro. The supplied record says a specially crafted PDF can trigger an out-of-bounds write, leading to potential memory corruption. Because the attack path involves opening or processing a malicious PDF, the main risk is to users and environments that routinely handle untrusted documents.

HIGH Gonitro CVE published 2017-02-10

CVE-2016-8711

CVE-2016-8711 describes a high-severity issue in Nitro Pro 10 / Nitro PDF Pro PDF parsing. According to NVD, a specially crafted PDF can trigger potential code execution, and the affected range extends through version 10.5.9.9. The CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) indicates the attack depends on user interaction: a victim must open or process the malicious PDF on the local endpoint.

HIGH Gonitro CVE published 2017-02-10

CVE-2016-8709

CVE-2016-8709 is a high-severity memory corruption vulnerability in Nitro Pro 10's PDF parsing functionality. According to NVD, a specially crafted PDF file can trigger a remote out-of-bounds write that may lead to memory corruption. The NVD CVSS v3.1 vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating user interaction is required and the impact can be severe once triggered. NVD lists affected Nitro [truncated]