Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Nitro PDF Pro for Windows 14.41.1.4 contains a NULL pointer dereference vulnerability in the JavaScript implementation of app.alert(). When app.alert() is called with more than one argument and the first argument evaluates to null (for example, app.alert(app.activeDocs, true) when app.activeDocs is null), the engine routes the call through a fallback path intended for non-string arguments. In this path, js_ValueToString() is invoked on the null value and returns an invalid string pointer, which is then passed to JS_GetStringChars() without validation. Dereferencing this pointer leads to an access violation and application crash when opening a crafted PDF.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Nitro PDF Pro 安全漏洞
Vulnerability Description
Nitro PDF Pro是美国Nitro公司的一个PDF编辑和管理工具。 Nitro PDF Pro 14.41.1.4版本存在安全漏洞,该漏洞源于app.alert函数存在空指针取消引用,可能导致应用程序崩溃。
CVSS Information
N/A
Vulnerability Type
N/A