Adobe Acrobat vulnerabilities
1,379 known vulnerabilities affecting adobe/acrobat.
Total CVEs
1,379
CISA KEV
24
actively exploited
Public exploits
46
Exploited in wild
41
Severity breakdown
CRITICAL538HIGH495MEDIUM320LOW26
Vulnerabilities
Page 58 of 69
CVE-2021-39855P4MEDIUMCVSS 6.5≥ 17.011.30059, ≤ 17.011.30199≥ 20.001.30005, ≤ 20.004.300062021-09-29
CVE-2021-39855 [MEDIUM] CWE-200 CVE-2021-39855: Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier
Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obtain NTLMv2 credentials. Exploitation of this issue requires user interaction in that a vict
nvd
CVE-2021-39856P4MEDIUMCVSS 6.5≥ 17.011.30059, ≤ 17.011.30199≥ 20.001.30005, ≤ 20.004.300062021-09-29
CVE-2021-39856 [MEDIUM] CWE-200 CVE-2021-39856: Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier
Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obtain NTLMv2 credentials. Exploitation of this issue requires user interaction in that a vict
nvd
CVE-2022-28258P4MEDIUMCVSS 5.5≥ 17.011.30059, ≤ 17.012.30205≥ 20.001.30005, ≤ 20.005.30314+1 more2022-05-11
CVE-2022-28258 [MEDIUM] CWE-125 CVE-2022-28258: Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (a
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR.
nvd
CVE-2022-28246P4MEDIUMCVSS 5.5≥ 17.011.30059, ≤ 17.012.30205≥ 20.001.30005, ≤ 20.005.30314+1 more2022-05-11
CVE-2022-28246 [MEDIUM] CWE-125 CVE-2022-28246: Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (a
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR.
nvd
CVE-2022-28263P4MEDIUMCVSS 5.5≥ 17.011.30059, ≤ 17.012.30205≥ 20.001.30005, ≤ 20.005.30314+1 more2022-05-11
CVE-2022-28263 [MEDIUM] CWE-125 CVE-2022-28263: Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (a
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR.
nvd
CVE-2022-28262P4MEDIUMCVSS 5.5≥ 17.011.30059, ≤ 17.012.30205≥ 20.001.30005, ≤ 20.005.30314+1 more2022-05-11
CVE-2022-28262 [MEDIUM] CWE-125 CVE-2022-28262: Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (a
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR.
nvd
CVE-2022-28248P4MEDIUMCVSS 5.5≥ 17.011.30059, ≤ 17.012.30205≥ 20.001.30005, ≤ 20.005.30314+1 more2022-05-11
CVE-2022-28248 [MEDIUM] CWE-125 CVE-2022-28248: Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (a
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR.
nvd
CVE-2011-0568P4MEDIUMCVSS 6.8v8.0v8.1+26 more2011-02-10
CVE-2011-0568 [MEDIUM] CVE-2011-0568: Unspecified vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x
Unspecified vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Mac OS X allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2004-0629P4HIGHCVSS 7.5v5.0v5.0.5+3 more2004-09-28
CVE-2004-0629 [HIGH] CVE-2004-0629: Buffer overflow in the ActiveX component (pdf.ocx) for Adobe Acrobat 5.0.5 and Acrobat Reader, and p
Buffer overflow in the ActiveX component (pdf.ocx) for Adobe Acrobat 5.0.5 and Acrobat Reader, and possibly other versions, allows remote attackers to execute arbitrary code via a URI for a PDF file with a null terminator (%00) followed by a long string.
nvd
CVE-2015-6697P4MEDIUMCVSS 6.8≥ 10.0, ≤ 10.1.15≥ 11.0.0, ≤ 11.0.122015-10-14
CVE-2015-6697 [MEDIUM] CWE-772 CVE-2015-6697: Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allow attackers to obtain sensitive information about color objects from process memory by reading a light object's RGB data, a differen
nvd
CVE-2014-9150P4MEDIUMCVSS 6.4≤ 11.0.8v11.0+7 more2014-11-30
CVE-2014-9150 [MEDIUM] CVE-2014-9150: Race condition in the MoveFileEx call hook feature in Adobe Reader and Acrobat 11.x before 11.0.09 o
Race condition in the MoveFileEx call hook feature in Adobe Reader and Acrobat 11.x before 11.0.09 on Windows allows attackers to bypass a sandbox protection mechanism, and consequently write to files in arbitrary locations, via an NTFS junction attack, a similar issue to CVE-2014-0568.
nvd
CVE-2024-39425P4HIGHCVSS 7.0≥ 20.001.30005, < 20.005.30655≥ 24.001.20604, < 24.001.301592024-08-14
CVE-2024-39425 [HIGH] CWE-367 CVE-2024-39425: Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affec
Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to privilege escalation. Exploitation of this issue require local low-privilege access to the affected system and attack complexity is high.
nvd
CVE-2021-28546P4MEDIUMCVSS 6.5≥ 17.011.30059, ≤ 17.011.30188≥ 20.001.30005, ≤ 20.001.300182021-04-01
CVE-2021-28546 [MEDIUM] CWE-353 CVE-2021-28546: Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are missing support for an integrity check. An unauthenticated attacker could leverage this vulnerability to modify content in a certified PDF without invalidating the certification. Exploitation of this issue requires user
nvd
CVE-2026-34626P4MEDIUMCVSS 6.3≥ 24.0.0, < 24.001.303652026-04-14
CVE-2026-34626 [MEDIUM] CWE-1321 CVE-2026-34626: Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Impr
Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary file system read in the context of the current user. Exploitation of this issue requires user interaction in that a vic
nvd
CVE-2017-3115P4MEDIUMCVSS 6.5≥ 11.0.0, < 11.0.212017-08-11
CVE-2017-3115 [MEDIUM] CWE-200 CVE-2017-3115: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an information disclosure vulnerability when handling links in a PDF document.
nvd
CVE-2008-5331P4HIGHCVSS 7.5v9v9.02008-12-05
CVE-2008-5331 [HIGH] CWE-310 CVE-2008-5331: Adobe Acrobat 9 uses more efficient encryption than previous versions, which makes it easier for att
Adobe Acrobat 9 uses more efficient encryption than previous versions, which makes it easier for attackers to guess a document's password via a brute-force attack.
nvd
CVE-2017-2947P4MEDIUMCVSS 5.5≤ 11.0.182017-01-11
CVE-2017-2947 [MEDIUM] CWE-20 CVE-2017-2947: Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlie
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have a security bypass vulnerability when manipulating Form Data Format (FDF).
nvd
CVE-2021-45063P4MEDIUMCVSS 5.5≥ 17.011.30059, ≤ 17.011.30204≥ 20.001.30005, ≤ 20.004.300172022-01-14
CVE-2021-45063 [MEDIUM] CWE-416 CVE-2021-45063: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of t
nvd
CVE-2021-44742P4MEDIUMCVSS 5.5≥ 17.011.30059, ≤ 17.011.30204≥ 20.001.30005, ≤ 20.004.300172022-01-14
CVE-2021-44742 [MEDIUM] CWE-125 CVE-2021-44742: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of th
nvd
CVE-2022-28244P4MEDIUMCVSS 6.3≥ 17.011.30059, ≤ 17.012.30205≥ 20.001.30005, ≤ 20.005.30314+1 more2022-05-11
CVE-2022-28244 [MEDIUM] CWE-657 CVE-2022-28244: Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by a violation of secure design principles through bypassing the content security policy, which could result in an attacker sending arbitrarily configured requests to the cross-origin attack target domain. Exploitation require
nvd