cbcvebase.

Adobe Acrobat vulnerabilities

1,379 known vulnerabilities affecting adobe/acrobat.

Total CVEs
1,379
CISA KEV
24
actively exploited
Public exploits
46
Exploited in wild
41
Severity breakdown
CRITICAL538HIGH495MEDIUM320LOW26

Vulnerabilities

Page 5 of 69
CVE-2020-24437P3HIGHCVSS 7.8≤ 20.001.300052020-11-05
CVE-2020-24437 [HIGH] CWE-416 CVE-2020-24437: Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a
nvd
CVE-2021-28554P3HIGHCVSS 7.8≥ 17.011.30180, ≤ 17.011.30196≥ 20.001.30005, ≤ 20.001.300252021-08-24
CVE-2021-28554 [HIGH] CWE-125 CVE-2021-28554: Acrobat Reader DC versions versions 2021.001.20155 (and earlier), 2020.001.30025 (and earlier) and 2 Acrobat Reader DC versions versions 2021.001.20155 (and earlier), 2020.001.30025 (and earlier) and 2017.011.30196 (and earlier) are affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires us
nvd
CVE-2021-39840P3HIGHCVSS 7.8≥ 20.001.30005, ≤ 20.004.30006≥ 17.011.30059, ≤ 17.011.301992021-09-29
CVE-2021-39840 [HIGH] CWE-416 CVE-2021-39840: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability when processing AcroForms that could result in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability in that the target m
nvd
CVE-2017-11263P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.20≥ 17.011.00000, ≤ 17.011.300662017-08-11
CVE-2017-11263 [HIGH] CWE-119 CVE-2017-11263: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the internal data structure manipulation related to document encoding. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2007-0044P4MEDIUMCVSS 4.3PoC≤ 7.0.8v7.0+8 more2007-01-03
CVE-2007-0044 [MEDIUM] CWE-352 CVE-2007-0044: Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."
nvd
CVE-2018-4890P3HIGHCVSS 8.8≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4890 [HIGH] CWE-787 CVE-2018-4890: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability is an instance of a heap overflow vulnerability in the image conversion engine, when handling JPEG data embedded within an XPS file. A successful attack can lead to code corrupti
nvd
CVE-2010-2889P3CRITICALCVSS 9.3v8.0v8.1+23 more2010-10-06
CVE-2010-2889 [CRITICAL] CWE-20 CVE-2010-2889: Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Window Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execute arbitrary code via a crafted font, a different vulnerability than CVE-2010-3626.
nvd
CVE-2011-4373P3CRITICALCVSS 9.8≤ 10.1.1≤ 9.4.6+3 more2012-01-10
CVE-2011-4373 [CRITICAL] CVE-2011-4373: Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-4370 and CVE-2011-4372.
nvd
CVE-2017-11211P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.20≥ 17.011.00000, ≤ 17.011.300662017-08-11
CVE-2017-11211 [HIGH] CWE-119 CVE-2017-11211: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in the JPEG parser. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2018-4910P3HIGHCVSS 8.8≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4910 [HIGH] CWE-787 CVE-2018-4910: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability is an instance of a heap overflow vulnerability in the JavaScript engine. The vulnerability is triggered by a PDF file with crafted JavaScript code that manipulates the optional
nvd
CVE-2021-44708P3HIGHCVSS 7.8≥ 17.011.30059, ≤ 17.011.30204≥ 20.001.30005, ≤ 20.004.300172022-01-14
CVE-2021-44708 [HIGH] CWE-122 CVE-2021-44708: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a heap overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vi
nvd
CVE-2018-4872P3CRITICALCVSS 10.0≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4872 [CRITICAL] CVE-2018-4872: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability is a security bypass vulnerability that leads to a sandbox escape. Specifically, the vulnerability exists in the way a cross call is handled.
nvd
CVE-2011-0567P3CRITICALCVSS 9.3v8.0v8.1+26 more2011-02-10
CVE-2011-0567 [CRITICAL] CVE-2011-0567: AcroRd32.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 AcroRd32.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted image that triggers an incorrect pointer calculation, leading to heap memory corruption, a different vulnerability than CVE-
nvd
CVE-2018-4895P3CRITICALCVSS 9.8≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4895 [CRITICAL] CWE-787 CVE-2018-4895: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the image conversion engine when processing Enhanced Metafile For
nvd
CVE-2021-28558P3HIGHCVSS 8.8≥ 17.011.30059, ≤ 17.011.30194≥ 20.001.30005, ≤ 20.001.300202021-09-02
CVE-2021-28558 [HIGH] CWE-122 CVE-2021-28558: Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2 Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Heap-based buffer overflow vulnerability in the PDFLibTool component. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Ex
nvd
CVE-2017-16368P3HIGHCVSS 8.8≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16368 [HIGH] CWE-119 CVE-2017-16368: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability leads to a stack-based buffer overflow condition in the internal Unicode string manipulation module. It is triggered by an invalid PDF f
nvd
CVE-2017-3117P3HIGHCVSS 8.8≥ 11.0.0, < 11.0.212017-08-11
CVE-2017-3117 [HIGH] CWE-119 CVE-2017-3117: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in the plugin that handles links within the PDF. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2014-8449P3CRITICALCVSS 10.0v10.0v10.0.1+25 more2014-12-10
CVE-2014-8449 [CRITICAL] CWE-189 CVE-2014-8449: Integer overflow in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows Integer overflow in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2017-16393P3HIGHCVSS 8.8≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16393 [HIGH] CWE-416 CVE-2017-16393: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the JavaScript engine. The mismatch between an old and a new object can provide an a
nvd
CVE-2018-4901P3HIGHCVSS 8.8≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4901 [HIGH] CWE-787 CVE-2018-4901: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the document identity representation. An attacker can potentially lev
nvd
Adobe Acrobat vulnerabilities | cvebase