Adobe Acrobat vulnerabilities
1,379 known vulnerabilities affecting adobe/acrobat.
Total CVEs
1,379
CISA KEV
24
actively exploited
Public exploits
46
Exploited in wild
41
Severity breakdown
CRITICAL538HIGH495MEDIUM320LOW26
Vulnerabilities
Page 54 of 69
CVE-2017-2972P3HIGHCVSS 7.8≤ 11.0.182017-01-24
CVE-2017-2972 [HIGH] CWE-119 CVE-2017-2972: Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlie
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion module related to JPEG parsing. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2018-4914P3MEDIUMCVSS 6.5≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4914 [MEDIUM] CWE-125 CVE-2018-4914: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070
An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the TIFF processing in the XPS engine. A successful atta
nvd
CVE-2018-4885P3MEDIUMCVSS 6.5≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4885 [MEDIUM] CWE-125 CVE-2018-4885: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070
An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of Enhanced Metafile Format processing engine (within the i
nvd
CVE-2018-4899P3MEDIUMCVSS 6.5≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4899 [MEDIUM] CWE-125 CVE-2018-4899: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070
An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the initial XPS page processing. A successful attack can
nvd
CVE-2018-4883P3MEDIUMCVSS 6.5≤ 17.011.300702018-02-27
CVE-2018-4883 [MEDIUM] CWE-125 CVE-2018-4883: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070
An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs because of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion engine that handles Enhanced Metafile F
nvd
CVE-2006-5857P3CRITICALCVSS 9.3≤ 7.0.8v3.0+23 more2006-12-31
CVE-2006-5857 [CRITICAL] CWE-399 CVE-2006-5857: Adobe Reader and Acrobat 7.0.8 and earlier allows user-assisted remote attackers to execute code via
Adobe Reader and Acrobat 7.0.8 and earlier allows user-assisted remote attackers to execute code via a crafted PDF file that triggers memory corruption and overwrites a subroutine pointer during rendering.
nvd
CVE-2018-4999P3MEDIUMCVSS 6.5≥ 17.011.30059, ≤ 17.011.300702018-07-09
CVE-2018-4999 [MEDIUM] CWE-125 CVE-2018-4999: Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, and 2015.0
Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, and 2015.006.30394 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
nvd
CVE-2023-21612P3HIGHCVSS 7.8≥ 20.001.30005, ≤ 20.005.304182023-01-18
CVE-2023-21612 [HIGH] CWE-379 CVE-2023-21612: Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.3041
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in privilege escalation in the context of the current user. Exploitation of this issue requires user interaction in that
nvd
CVE-2023-21611P3HIGHCVSS 7.8≥ 20.001.30005, ≤ 20.005.304182023-01-18
CVE-2023-21611 [HIGH] CWE-379 CVE-2023-21611: Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.3041
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in privilege escalation in the context of the current user. Exploitation of this issue requires user interaction in that
nvd
CVE-2025-27161P3HIGHCVSS 7.8≥ 20.001.30002, < 20.005.30763≥ 24.0.0, < 24.001.302352025-03-11
CVE-2025-27161 [HIGH] CWE-125 CVE-2025-27161: Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-
Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this
nvd
CVE-2015-5091P3HIGHCVSS 7.8≥ 10.0, < 10.1.15≥ 11.0.0, < 11.0.122015-07-15
CVE-2015-5091 [HIGH] CWE-20 CVE-2015-5091: Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to cause a denial of service via invalid data.
nvd
CVE-2017-11232P3MEDIUMCVSS 6.5≥ 11.0.0, ≤ 11.0.20≥ 17.011.00000, ≤ 17.011.300662017-08-11
CVE-2017-11232 [MEDIUM] CWE-200 CVE-2017-11232: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability when processing Enhanced Metafile Format (EMF) data related to brush manipulation. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2009-2028P3CRITICALCVSS 10.0v7.0v7.0.1+21 more2009-06-11
CVE-2009-2028 [CRITICAL] CVE-2009-2028: Multiple unspecified vulnerabilities in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 an
Multiple unspecified vulnerabilities in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 have unknown impact and attack vectors, related to "Adobe internally discovered issues."
nvd
CVE-2010-0196P3CRITICALCVSS 9.3v9.0v9.1+17 more2010-04-14
CVE-2010-0196 [CRITICAL] CVE-2010-0196: Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Wind
Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2010-0192 and CVE-2010-0193.
nvd
CVE-2009-2996P3CRITICALCVSS 9.3≤ 9.1.3v7.0+22 more2009-10-19
CVE-2009-2996 [CRITICAL] CVE-2009-2996: Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allow attackers to c
Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-2985.
nvd
CVE-2009-2985P3CRITICALCVSS 9.3≤ 9.1.3v7.0+22 more2009-10-19
CVE-2009-2985 [CRITICAL] CWE-399 CVE-2009-2985: Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allow attackers to c
Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-2996.
nvd
CVE-2020-24428P3HIGHCVSS 7.7≤ 20.001.300052020-11-05
CVE-2020-24428 [HIGH] CWE-367 CVE-2020-24428: Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) for macOS are affected by a time-of-check time-of-use (TOCTOU) race condition vulnerability that could result in local privilege escalation. Exploitation of this issue requires user interaction in that a victim must open a malicious f
nvd
CVE-2011-0564P3CRITICALCVSS 9.3v8.0v8.1+26 more2011-02-10
CVE-2011-0564 [CRITICAL] CWE-264 CVE-2011-0564: Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows use w
Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows use weak permissions for unspecified files, which allows attackers to gain privileges via unknown vectors.
nvd
CVE-2022-35672P3HIGHCVSS 7.8≥ 20.001.30005, ≤ 20.005.30314≥ 20.001.30005, ≤ 20.005.30311+1 more2022-07-27
CVE-2022-35672 [HIGH] CWE-125 CVE-2022-35672: Adobe Acrobat Reader version 22.001.20085 (and earlier), 20.005.30314 (and earlier) and 17.012.30205
Adobe Acrobat Reader version 22.001.20085 (and earlier), 20.005.30314 (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of t
nvd
CVE-2026-47937P3HIGHCVSS 7.7≥ 24.0.0, < 24.001.303832026-06-09
CVE-2026-47937 [HIGH] CWE-427 CVE-2026-47937: Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Searc
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interact
nvd