cbcvebase.

Adobe Acrobat vulnerabilities

1,379 known vulnerabilities affecting adobe/acrobat.

Total CVEs
1,379
CISA KEV
24
actively exploited
Public exploits
46
Exploited in wild
41
Severity breakdown
CRITICAL538HIGH495MEDIUM320LOW26

Vulnerabilities

Page 2 of 69
CVE-2014-0496P1HIGHCVSS 8.8KEV≥ 10.0, < 10.1.9≥ 11.0, < 11.0.62014-01-15
CVE-2014-0496 [HIGH] CWE-416 CVE-2014-0496: Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2023-26369P1HIGHCVSS 7.8KEV≥ 20.001.3005, < 20.005.305242023-09-13
CVE-2023-26369 [HIGH] CWE-787 CVE-2023-26369: Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2008-0655P2HIGHCVSS 8.8KEVfixed in 8.1.22008-02-07
CVE-2008-0655 [HIGH] CWE-200 CVE-2008-0655: Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact an Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.
nvd
CVE-2009-1862P2HIGHCVSS 7.8KEV≥ 9.0, ≤ 9.1.22009-07-23
CVE-2009-1862 [HIGH] CWE-787 CVE-2009-1862: Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exp
nvd
CVE-2009-0658P1HIGHCVSS 7.8ExploitedPoC≥ 7.0, ≤ 7.1.1≥ 8.0, ≤ 8.1.4+1 more2009-02-20
CVE-2009-0658 [HIGH] CWE-119 CVE-2009-0658: Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attacker Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream, as exploited in the wild in February 2009 by Trojan.Pidief.E.
nvd
CVE-2010-3654P2CRITICALCVSS 9.3ExploitedPoCv9.0v9.1+10 more2010-10-29
CVE-2010-3654 [CRITICAL] CWE-119 CVE-2010-3654: Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Sol Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and applica
nvd
CVE-2009-2990P2CRITICALCVSS 9.3ExploitedPoC≤ 9.1.3v7.0+22 more2009-10-19
CVE-2009-2990 [CRITICAL] CWE-189 CVE-2009-2990: Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x thr Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2010-2862P2CRITICALCVSS 9.3ExploitedPoCv9.3.32010-08-05
CVE-2010-2862 [CRITICAL] CWE-189 CVE-2010-2862: Integer overflow in CoolType.dll in Adobe Reader 8.2.3 and 9.3.3, and Acrobat 9.3.3, allows remote a Integer overflow in CoolType.dll in Adobe Reader 8.2.3 and 9.3.3, and Acrobat 9.3.3, allows remote attackers to execute arbitrary code via a TrueType font with a large maxCompositePoints value in a Maximum Profile (maxp) table.
nvd
CVE-2009-1492P2CRITICALCVSS 9.3ExploitedPoC≥ 7.0, ≤ 7.1.1≥ 8.0, ≤ 8.1.4+1 more2009-04-30
CVE-2009-1492 [CRITICAL] CWE-399 CVE-2009-1492: The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and ea The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments
nvd
CVE-2024-41869P2HIGHCVSS 7.8Exploitedfixed in 20.005.30680≥ 24.001.0, < 24.001.301872024-09-13
CVE-2024-41869 [HIGH] CWE-416 CVE-2024-41869: Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affec Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2010-2884P2CRITICALCVSS 9.3Exploited≤ 9.3.4v3.0+54 more2010-09-15
CVE-2010-2884 [CRITICAL] CVE-2010-2884: Adobe Flash Player 10.1.82.76 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.92.10 on Adobe Flash Player 10.1.82.76 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.92.10 on Android; authplay.dll in Adobe Reader and Acrobat 9.x before 9.4; and authplay.dll in Adobe Reader and Acrobat 8.x before 8.2.5 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unsp
nvd
CVE-2017-16383P2HIGHCVSS 8.8Exploited≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16383 [HIGH] CWE-119 CVE-2017-16383: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a heap overflow vulnerability when processing a JPEG file embedded within an XPS document.
nvd
CVE-2023-26397P1MEDIUMCVSS 5.5Exploited≥ 20.001.3005, ≤ 20.005.304412023-04-12
CVE-2023-26397 [MEDIUM] CWE-125 CVE-2023-26397: Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must ope
nvd
CVE-2017-16391P2HIGHCVSS 8.8Exploited≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16391 [HIGH] CWE-129 CVE-2017-16391: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is a result of untrusted input that is used to calculate an array index; the calculation occurs in the printing functionality. The vulner
nvd
CVE-2018-4893P2MEDIUMCVSS 6.5Exploited≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4893 [MEDIUM] CWE-125 CVE-2018-4893: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of XPS font processing. A successful attack can lead to sen
nvd
CVE-2011-4369P2CRITICALCVSS 10.0Exploitedv9.0v9.1+22 more2011-12-16
CVE-2011-4369 [CRITICAL] CVE-2011-4369: Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windo Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6 on Mac OS X, Adobe Reader and Acrobat 10.x through 10.1.1 on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX allows remote attackers to execute arbitrary code or cause a denial of service (memory
nvd
CVE-2011-2107P2MEDIUMCVSS 4.3Exploited≤ 10.0.3v9.0+18 more2011-06-09
CVE-2011-2107 [MEDIUM] CWE-79 CVE-2011-2107: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.181.22 on Windows, Mac OS Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.181.22 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.22 and earlier on Android, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "universal cross-site scripting vulnerability."
nvd
CVE-2007-5020P2CRITICALCVSS 9.3Exploitedv8.12007-09-21
CVE-2007-5020 [CRITICAL] CWE-94 CVE-2007-5020: Unspecified vulnerability in Adobe Acrobat and Reader 8.1 on Windows allows remote attackers to exec Unspecified vulnerability in Adobe Acrobat and Reader 8.1 on Windows allows remote attackers to execute arbitrary code via a crafted PDF file, related to the mailto: option and Internet Explorer 7 on Windows XP. NOTE: this information is based upon a vague pre-advisory by a reliable researcher.
nvd
CVE-2016-4119P2CRITICALCVSS 9.8Exploited≤ 11.0.162016-08-26
CVE-2016-4119 [CRITICAL] CVE-2016-4119: Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1037, CVE-2016-1063
nvd
CVE-2009-3957P2MEDIUMCVSS 5.0Exploited≤ 9.2v3.0+45 more2010-01-13
CVE-2009-3957 [MEDIUM] CVE-2009-3957: Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow att Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow attackers to cause a denial of service (NULL pointer dereference) via unspecified vectors.
nvd
Adobe Acrobat vulnerabilities | cvebase