cbcvebase.

Adobe Acrobat vulnerabilities

1,379 known vulnerabilities affecting adobe/acrobat.

Total CVEs
1,379
CISA KEV
24
actively exploited
Public exploits
46
Exploited in wild
41
Severity breakdown
CRITICAL538HIGH495MEDIUM320LOW26

Vulnerabilities

Page 43 of 69
CVE-2023-38229P3HIGHCVSS 7.8≥ 20.001.30005, ≤ 20.005.30516.10516≥ 20.001.30005, < 20.005.30514.105142023-08-10
CVE-2023-38229 [HIGH] CWE-125 CVE-2023-38229: Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2023-38223P3HIGHCVSS 7.8≥ 20.001.30005, ≤ 20.005.30516.10516≥ 20.001.30005, < 20.005.30514.105142023-08-10
CVE-2023-38223 [HIGH] CWE-824 CVE-2023-38223: Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Access of Uninitialized Pointer that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2010-2212P3CRITICALCVSS 9.3v9.0v9.1+19 more2010-06-30
CVE-2010-2212 [CRITICAL] CVE-2010-2212: Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Ma Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a PDF file containing Flash content with a crafted #1023 (3FFh) tag, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2
nvd
CVE-2023-38234P3HIGHCVSS 7.8≥ 20.001.30005, ≤ 20.005.30516.10516≥ 20.001.30005, < 20.005.30514.105142023-08-10
CVE-2023-38234 [HIGH] CWE-824 CVE-2023-38234: Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2010-2210P3CRITICALCVSS 9.3v9.0v9.1+19 more2010-06-30
CVE-2010-2210 [CRITICAL] CVE-2010-2210: Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attac Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2211, and CVE-2010-2212.
nvd
CVE-2017-2952P3HIGHCVSS 7.8≤ 11.0.182017-01-11
CVE-2017-2952 [HIGH] CWE-119 CVE-2017-2952: Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlie Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable buffer overflow / underflow vulnerability in the image conversion module related to parsing tags in TIFF files. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2011-0610P3CRITICALCVSS 9.3v9.0v9.1+16 more2011-05-03
CVE-2011-0610 [CRITICAL] CWE-119 CVE-2011-0610: The CoolType library in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Read The CoolType library in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecifie
nvd
CVE-2017-2942P3HIGHCVSS 7.8≤ 11.0.182017-01-11
CVE-2017-2942 [HIGH] CWE-119 CVE-2017-2942: Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlie Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability when processing TIFF image data. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2015-6713P3HIGHCVSS 7.5≥ 10.0, ≤ 10.1.15≥ 11.0.0, ≤ 11.0.122015-10-14
CVE-2015-6713 [HIGH] CVE-2015-6713: The Function call implementation in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11. The Function call implementation in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnera
nvd
CVE-2025-64785P3HIGHCVSS 7.8≥ 20.001.3005, < 20.005.30838≥ 24.001.20604, < 24.001.30307+1 more2025-12-09
CVE-2025-64785 [HIGH] CWE-426 CVE-2025-64785: Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and ear Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a search path to locate critical resources such as programs, an attacker could m
nvd
CVE-2025-54257P3HIGHCVSS 7.8≥ 24.0.0, < 24.001.30264≥ 20.001.30002, < 20.005.30793+1 more2025-09-09
CVE-2025-54257 [HIGH] CWE-416 CVE-2025-54257: Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use A Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file, and scope is unchanged.
nvd
CVE-2026-27278P3HIGHCVSS 7.8≥ 24.001.20604, < 24.001.303562026-03-10
CVE-2026-27278 [HIGH] CWE-416 CVE-2026-27278: Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use A Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-47916P3HIGHCVSS 7.8≥ 24.0.0, < 24.001.303832026-06-09
CVE-2026-47916 [HIGH] CWE-416 CVE-2026-47916: Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vuln Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-47959P3HIGHCVSS 7.8fixed in 24.001.30383fixed in 26.001.216622026-06-09
CVE-2026-47959 [HIGH] CWE-121 CVE-2026-47959: Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Stack-based Buffer Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-47921P3HIGHCVSS 7.8≥ 24.0.0, < 24.001.303832026-06-09
CVE-2026-47921 [HIGH] CWE-416 CVE-2026-47921: Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vuln Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-47920P3HIGHCVSS 7.8≥ 24.0.0, < 24.001.303832026-06-09
CVE-2026-47920 [HIGH] CWE-416 CVE-2026-47920: Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vuln Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-47955P3HIGHCVSS 7.8≥ 24.0.0, < 24.001.303832026-06-09
CVE-2026-47955 [HIGH] CWE-416 CVE-2026-47955: Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vuln Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2015-7614P3MEDIUMCVSS 6.8≥ 10.0, ≤ 10.1.15≥ 11.0.0, ≤ 11.0.122015-10-14
CVE-2015-7614 [MEDIUM] CVE-2015-7614: Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions and execute arbitrary commands via an app.launchURL call, a different vulnerabil
nvd
CVE-2009-2993P3CRITICALCVSS 9.3≤ 9.1.3v7.0+22 more2009-10-19
CVE-2009-2993 [CRITICAL] CWE-20 CVE-2009-2993: The JavaScript for Acrobat API in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9 The JavaScript for Acrobat API in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 does not properly implement the (1) Privileged Context and (2) Safe Path restrictions for unspecified JavaScript methods, which allows remote attackers to create arbitrary files, and possibly execute arbitrary code, via the cPath paramete
nvd
CVE-2011-2106P3CRITICALCVSS 9.3v8.0v8.1+34 more2011-06-16
CVE-2011-2106 [CRITICAL] CWE-119 CVE-2011-2106: Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Mac OS X allow at Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
Adobe Acrobat vulnerabilities | cvebase