Adobe Acrobat vulnerabilities
1,356 known vulnerabilities affecting adobe/acrobat.
Total CVEs
1,356
CISA KEV
23
actively exploited
Public exploits
43
Exploited in wild
27
Severity breakdown
CRITICAL540HIGH476MEDIUM316LOW24
Vulnerabilities
Page 17 of 68
CVE-2021-39836HIGHCVSS 7.8≥ 17.011.30059, ≤ 17.011.30199≥ 20.001.30005, ≤ 20.004.300062021-09-29
CVE-2021-39836 [HIGH] CWE-416 CVE-2021-39836: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm buttonGetIcon action that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti
nvd
CVE-2021-39840HIGHCVSS 7.8≥ 20.001.30005, ≤ 20.004.30006≥ 17.011.30059, ≤ 17.011.301992021-09-29
CVE-2021-39840 [HIGH] CWE-416 CVE-2021-39840: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability when processing AcroForms that could result in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability in that the target m
nvd
CVE-2021-39841HIGHCVSS 7.8≥ 20.001.30005, ≤ 20.004.30006≥ 17.011.30059, ≤ 17.011.301992021-09-29
CVE-2021-39841 [HIGH] CWE-843 CVE-2021-39841: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Type Confusion vulnerability. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must ope
nvd
CVE-2021-39842HIGHCVSS 7.8≥ 20.001.30005, ≤ 20.004.30006≥ 17.011.30059, ≤ 17.011.301992021-09-29
CVE-2021-39842 [HIGH] CWE-416 CVE-2021-39842: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2021-39839HIGHCVSS 7.8≥ 20.001.30005, ≤ 20.004.30006≥ 17.011.30059, ≤ 17.011.301992021-09-29
CVE-2021-39839 [HIGH] CWE-416 CVE-2021-39839: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm getItem action that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in
nvd
CVE-2021-39837HIGHCVSS 7.8≥ 20.001.30005, ≤ 20.004.30006≥ 17.011.30059, ≤ 17.011.301992021-09-29
CVE-2021-39837 [HIGH] CWE-416 CVE-2021-39837: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm deleteItemAt action that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interactio
nvd
CVE-2021-39846MEDIUMCVSS 6.1≥ 20.001.30005, ≤ 20.004.30006≥ 17.011.30059, ≤ 17.011.301992021-09-29
CVE-2021-39846 [MEDIUM] CWE-121 CVE-2021-39846: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted PDF file, potentially resulting in memory corruption in the context of the current user. Exploitation requires user interaction in that a victim mu
nvd
CVE-2021-39845MEDIUMCVSS 6.1≥ 20.001.30005, ≤ 20.004.30006≥ 17.011.30059, ≤ 17.011.301992021-09-29
CVE-2021-39845 [MEDIUM] CWE-121 CVE-2021-39845: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted PDF file, potentially resulting in memory corruption in the context of the current user. Exploitation requires user interaction in that a victim mu
nvd
CVE-2021-39854MEDIUMCVSS 5.5≥ 17.011.30059, ≤ 17.011.30199≥ 20.001.30005, ≤ 20.004.300062021-09-29
CVE-2021-39854 [MEDIUM] CWE-476 CVE-2021-39854: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requi
nvd
CVE-2021-39852MEDIUMCVSS 5.5≥ 17.011.30059, ≤ 17.011.30199≥ 20.001.30005, ≤ 20.004.300062021-09-29
CVE-2021-39852 [MEDIUM] CWE-476 CVE-2021-39852: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requi
nvd
CVE-2021-39860MEDIUMCVSS 5.5≥ 17.011.30059, ≤ 17.011.30199≥ 20.001.30005, ≤ 20.004.300062021-09-29
CVE-2021-39860 [MEDIUM] CWE-476 CVE-2021-39860: Acrobat Pro DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3019
Acrobat Pro DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive user memory. Exploitation of this issue requires user interaction in that a victim must open
nvd
CVE-2021-39851MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.004.30006≥ 17.011.30059, ≤ 17.011.301992021-09-29
CVE-2021-39851 [MEDIUM] CWE-476 CVE-2021-39851: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requi
nvd
CVE-2021-39849MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.004.30006≥ 17.011.30059, ≤ 17.011.301992021-09-29
CVE-2021-39849 [MEDIUM] CWE-476 CVE-2021-39849: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requi
nvd
CVE-2021-39853MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.004.300062021-09-29
CVE-2021-39853 [MEDIUM] CWE-476 CVE-2021-39853: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requi
nvd
CVE-2021-39857MEDIUMCVSS 4.3≥ 17.011.30059, ≤ 17.011.30199≥ 20.001.30005, ≤ 20.004.300062021-09-29
CVE-2021-39857 [MEDIUM] CWE-200 CVE-2021-39857: Adobe Acrobat Reader DC add-on for Internet Explorer versions 2021.005.20060 (and earlier), 2020.004
Adobe Acrobat Reader DC add-on for Internet Explorer versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to check for existence of local files. Exploitation of this issue requires use
nvd
CVE-2021-39855MEDIUMCVSS 6.5≥ 17.011.30059, ≤ 17.011.30199≥ 20.001.30005, ≤ 20.004.300062021-09-29
CVE-2021-39855 [MEDIUM] CWE-200 CVE-2021-39855: Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier
Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obtain NTLMv2 credentials. Exploitation of this issue requires user interaction in that a vict
nvd
CVE-2021-39861MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.004.300062021-09-29
CVE-2021-39861 [MEDIUM] CWE-125 CVE-2021-39861: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a
nvd
CVE-2021-39856MEDIUMCVSS 6.5≥ 17.011.30059, ≤ 17.011.30199≥ 20.001.30005, ≤ 20.004.300062021-09-29
CVE-2021-39856 [MEDIUM] CWE-200 CVE-2021-39856: Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier
Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obtain NTLMv2 credentials. Exploitation of this issue requires user interaction in that a vict
nvd
CVE-2021-39850MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.004.30006≥ 17.011.30059, ≤ 17.011.301992021-09-29
CVE-2021-39850 [MEDIUM] CWE-476 CVE-2021-39850: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requi
nvd
CVE-2021-39844LOWCVSS 3.3≥ 20.001.30005, ≤ 20.004.30006≥ 17.011.30059, ≤ 17.011.301992021-09-29
CVE-2021-39844 [LOW] CWE-125 CVE-2021-39844: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal
nvd