Adobe Acrobat vulnerabilities
1,379 known vulnerabilities affecting adobe/acrobat.
Total CVEs
1,379
CISA KEV
24
actively exploited
Public exploits
46
Exploited in wild
41
Severity breakdown
CRITICAL538HIGH495MEDIUM320LOW26
Vulnerabilities
Page 57 of 69
CVE-2015-5086P3MEDIUMCVSS 6.8≥ 10.0, ≤ 10.1.14≥ 11.0.0, ≤ 11.0.112015-07-15
CVE-2015-5086 [MEDIUM] CVE-2015-5086: Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-4435, CVE-2015-
nvd
CVE-2017-3012P3HIGHCVSS 7.8≤ 11.0.192017-04-12
CVE-2017-3012 [HIGH] CWE-427 CVE-2017-3012: Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlie
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an insecure library loading (DLL hijacking) vulnerability in the OCR plugin.
nvd
CVE-2009-2982P3CRITICALCVSS 9.3≤ 9.1.3v7.0+22 more2009-10-19
CVE-2009-2982 [CRITICAL] CWE-310 CVE-2009-2982: An unspecified certificate in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibl
An unspecified certificate in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow remote attackers to conduct a "social engineering attack" via unknown vectors.
nvd
CVE-2017-3118P3MEDIUMCVSS 6.5≥ 11.0.0, < 11.0.212017-08-11
CVE-2017-3118 [MEDIUM] CWE-200 CVE-2017-3118: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has a security bypass vulnerability related to execution of malicious attachments.
nvd
CVE-2017-16369P3MEDIUMCVSS 6.5≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16369 [MEDIUM] CWE-200 CVE-2017-16369: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a Same Origin Policy security bypass vulnerability, affecting files on the local system, etc.
nvd
CVE-2009-3460P3CRITICALCVSS 9.3≤ 9.1.3v7.0+22 more2009-10-19
CVE-2009-3460 [CRITICAL] CWE-399 CVE-2009-3460: Adobe Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 allows attackers to c
Adobe Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.
nvd
CVE-2014-0563P3HIGHCVSS 7.8v10.0v10.0.1+23 more2014-09-17
CVE-2014-0563 [HIGH] CWE-119 CVE-2014-0563: Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allow attac
Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allow attackers to cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2021-44715P4MEDIUMCVSS 5.5≥ 17.011.30059, ≤ 17.011.30204≥ 20.001.30005, ≤ 20.004.300172022-01-14
CVE-2021-44715 [MEDIUM] CWE-125 CVE-2021-44715: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR.
nvd
CVE-2015-5106P3MEDIUMCVSS 6.8≥ 10.0, < 10.1.15≥ 11.0.0, < 11.0.122015-07-15
CVE-2015-5106 [MEDIUM] CVE-2015-5106: Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and perform a transition from Low Integrity to Medium Integrity via unspecified vectors,
nvd
CVE-2005-2470P4HIGHCVSS 7.5v5.0v5.0.5+6 more2005-08-16
CVE-2005-2470 [HIGH] CVE-2005-2470: Buffer overflow in a "core application plug-in" for Adobe Reader 5.1 through 7.0.2 and Acrobat 5.0 t
Buffer overflow in a "core application plug-in" for Adobe Reader 5.1 through 7.0.2 and Acrobat 5.0 through 7.0.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.
nvd
CVE-2004-0632P3HIGHCVSS 7.5v6.0v6.0.12004-07-27
CVE-2004-0632 [HIGH] CVE-2004-0632: Adobe Reader 6.0 does not properly handle null characters when splitting a filename path into compon
Adobe Reader 6.0 does not properly handle null characters when splitting a filename path into components, which allows remote attackers to execute arbitrary code via a file with a long extension that is not normally handled by Reader, triggering a buffer overflow.
nvd
CVE-2021-28555P3MEDIUMCVSS 6.5≥ 17.011.30059, ≤ 17.011.30194≥ 20.001.30005, ≤ 20.001.300202021-09-02
CVE-2021-28555 [MEDIUM] CWE-125 CVE-2021-28555: Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to get access to sensitive information in the context of the current user. Exploitation of this issue requir
nvd
CVE-2017-16361P4MEDIUMCVSS 6.5≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16361 [MEDIUM] CVE-2017-16361: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a security bypass vulnerability when handling XFDF files.
nvd
CVE-2011-0605P4MEDIUMCVSS 6.8v8.0v8.1+26 more2011-02-10
CVE-2011-0605 [MEDIUM] CWE-119 CVE-2011-0605: Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Mac OS X allo
Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2011-2105P3CRITICALCVSS 9.3v8.0v8.1+34 more2011-06-16
CVE-2011-2105 [CRITICAL] CWE-119 CVE-2011-2105: Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac O
Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allow attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted font data.
nvd
CVE-2010-2203P4MEDIUMCVSS 6.8v9.0v9.1+7 more2010-06-30
CVE-2010-2203 [MEDIUM] CWE-119 CVE-2010-2203: Adobe Reader and Acrobat 9.x before 9.3.3 on UNIX allow attackers to execute arbitrary code or cause
Adobe Reader and Acrobat 9.x before 9.3.3 on UNIX allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2009-3461P4CRITICALCVSS 9.3v9.0.0v9.1+3 more2009-10-19
CVE-2009-3461 [CRITICAL] CWE-264 CVE-2009-3461: Unspecified vulnerability in Adobe Acrobat 9.x before 9.2 allows attackers to bypass intended file-e
Unspecified vulnerability in Adobe Acrobat 9.x before 9.2 allows attackers to bypass intended file-extension restrictions via unknown vectors.
nvd
CVE-2006-3453P3MEDIUMCVSS 5.1v6.0v6.0.1+3 more2006-07-13
CVE-2006-3453 [MEDIUM] CVE-2006-3453: Buffer overflow in Adobe Acrobat 6.0 to 6.0.4 allows remote attackers to execute arbitrary code via
Buffer overflow in Adobe Acrobat 6.0 to 6.0.4 allows remote attackers to execute arbitrary code via unknown vectors in a document that triggers the overflow when it is distilled to PDF.
nvd
CVE-2014-8453P4MEDIUMCVSS 5.0v10.0v10.0.1+25 more2014-12-10
CVE-2014-8453 [MEDIUM] CWE-264 CVE-2014-8453: Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow remot
Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2009-3462P4MEDIUMCVSS 5.1≤ 9.1.3v7.0+22 more2009-10-19
CVE-2009-3462 [MEDIUM] CVE-2009-3462: Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 on Unix, when Debug
Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 on Unix, when Debug mode is enabled, allow attackers to execute arbitrary code via unspecified vectors, related to a "format bug."
nvd