← Vulnerability feed

Vulnerability record · CVE-2020-6116 · published 17 September 2020

CVE-2020-6116: Gonitro nitro pro integer overflow vulnerability

Gonitro · Nitro Pro

An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. When drawing the contents of a page using colors from an indexed colorspace, the application can miscalculate the size of a buffer when allocating space for its colors. When using this allocated buffer, the application can write outside its bounds and cause memory corruption which can lead to code execution. A specially crafted document must be loaded by a victim in order to trigger this vulnerability.

7.8 CVSS 3.1 High EPSS 28% · top 1.9% CWE-680 · CWE-680CWE-131 · CWE-131
7.8CVSS 3.1 base score, v2 6.8
28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. When drawing the contents of a page using colors from an indexed colorspace, the application can miscalculate the size of a buffer when allocating space for its colors. When using this allocated buffer, the application can write outside its bounds and cause memory corruption which can lead to code execution. A specially crafted document must be loaded by a victim in order to trigger this vulnerability.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-6116 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-6146Nitro Pro heap buffer overflow in ICCBased colorspace stroke renderingNitro Pro 13.13.2.242 and 13.16.2.300 contain a heap-based buffer overflow when rendering a page and selecting the stroke color from an ICCBased colo…EPSS 76%analysed8.8CVE-2020-6074Gonitro nitro pro use after free vulnerabilityAn exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF document can cause a use-after-…EPSS 41%8.8CVE-2017-7442Gonitro nitro pro path traversal vulnerabilityNitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.EPSS 41%8.1CVE-2020-10223Gonitro nitro pro out-of-bounds write vulnerabilitynpdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPDAnnotHandlerUtils::create_pop…EPSS 2.5%8.1CVE-2020-10222Gonitro nitro pro vulnerabilitynpdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to Heap Corruption at npdf!nitro::get_property+2381 via a crafted PDF document.EPSS 2.5%7.8CVE-2021-21796Gonitro nitro pro use after free vulnerabilityAn exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an objec…EPSS 16%7.8CVE-2021-21797Gonitro nitro pro double free vulnerabilityAn exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference…EPSS 15%7.8CVE-2021-21798Gonitro nitro pro vulnerabilityAn exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document …EPSS 16%

Source: NIST National Vulnerability Database (record CVE-2020-6116), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.