← Vulnerability feed

Vulnerability record · CVE-2017-7950 · published 7 July 2017

CVE-2017-7950: Gonitro nitro pro improper input validation vulnerability

Gonitro · Nitro Pro

Nitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX file.

5.5 CVSS 3.0 Medium EPSS 2.5% · top 15.9% CWE-20 · Improper input validation
5.5CVSS 3.0 base score, v2 4.3
2.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Nitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX file.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-7950 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-6146Nitro Pro heap buffer overflow in ICCBased colorspace stroke renderingNitro Pro 13.13.2.242 and 13.16.2.300 contain a heap-based buffer overflow when rendering a page and selecting the stroke color from an ICCBased colo…EPSS 76%analysed8.8CVE-2020-6074Gonitro nitro pro use after free vulnerabilityAn exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF document can cause a use-after-…EPSS 41%8.8CVE-2017-7442Gonitro nitro pro path traversal vulnerabilityNitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.EPSS 41%8.1CVE-2020-10223Gonitro nitro pro out-of-bounds write vulnerabilitynpdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPDAnnotHandlerUtils::create_pop…EPSS 2.5%8.1CVE-2020-10222Gonitro nitro pro vulnerabilitynpdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to Heap Corruption at npdf!nitro::get_property+2381 via a crafted PDF document.EPSS 2.5%7.8CVE-2021-21797Gonitro nitro pro double free vulnerabilityAn exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference…EPSS 15%7.8CVE-2021-21796Gonitro nitro pro use after free vulnerabilityAn exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an objec…EPSS 16%7.8CVE-2021-21798Gonitro nitro pro vulnerabilityAn exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document …EPSS 16%

Source: NIST National Vulnerability Database (record CVE-2017-7950), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.