CVE-2016-8709: Gonitro Nitro PDF Pro

High severity, CVSS 7.8. EPSS: 1.3% chance of exploitation in the next 30 days.

A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A specially crafted PDF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim a specific PDF file to trigger this vulnerability.

Affected products

  • Gonitro Nitro PDF Pro: up to and including 10.5.9.9

Published 2017-02-10. Last modified 2026-06-17.