CVE-2016-8709 HIGH

CVE-2016-8709

Vendor Nitro
Product Nitro Pro
Published February 10, 2017
Last update August 6, 2024

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A specially crafted PDF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim a specific PDF file to trigger this vulnerability.

Key dates

02Disclosure timeline

February 10, 2017 CVE published
August 6, 2024 Record updated