Adobe Acrobat vulnerabilities
1,379 known vulnerabilities affecting adobe/acrobat.
Total CVEs
1,379
CISA KEV
24
actively exploited
Public exploits
46
Exploited in wild
41
Severity breakdown
CRITICAL538HIGH495MEDIUM320LOW26
Vulnerabilities
Page 61 of 69
CVE-2023-44358P4MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.005.305392023-11-16
CVE-2023-44358 [MEDIUM] CWE-125 CVE-2023-44358: Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected
Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must ope
nvd
CVE-2023-44356P4MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.005.305392023-11-16
CVE-2023-44356 [MEDIUM] CWE-125 CVE-2023-44356: Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected
Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must ope
nvd
CVE-2023-44357P4MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.005.305392023-11-16
CVE-2023-44357 [MEDIUM] CWE-125 CVE-2023-44357: Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected
Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must ope
nvd
CVE-2023-44340P4MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.005.305392023-11-16
CVE-2023-44340 [MEDIUM] CWE-125 CVE-2023-44340: Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected
Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must ope
nvd
CVE-2023-44339P4MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.005.305392023-11-16
CVE-2023-44339 [MEDIUM] CWE-125 CVE-2023-44339: Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected
Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must ope
nvd
CVE-2024-30311P4MEDIUMCVSS 5.5≥ 20.001.30002, < 20.005.30635≥ 20.001.30002, < 20.005.306362024-05-15
CVE-2024-30311 [MEDIUM] CWE-125 CVE-2024-30311: Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bou
Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious fil
nvd
CVE-2015-3047P4MEDIUMCVSS 5.0v10.1.0v10.1.1+23 more2015-05-13
CVE-2015-3047 [MEDIUM] CVE-2015-3047: Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attac
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to cause a denial of service (NULL pointer dereference) via unspecified vectors.
nvd
CVE-2024-30312P4MEDIUMCVSS 5.5≥ 20.001.30002, < 20.005.30635≥ 20.001.30002, < 20.005.306362024-05-15
CVE-2024-30312 [MEDIUM] CWE-125 CVE-2024-30312: Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bou
Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious fil
nvd
CVE-2021-28559P4MEDIUMCVSS 5.3≥ 17.011.30059, ≤ 17.011.30194≥ 20.001.30005, ≤ 20.001.300202021-09-02
CVE-2021-28559 [MEDIUM] CWE-359 CVE-2021-28559: Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Information Exposure vulnerability. An unauthenticated attacker could leverage this vulnerability to get access to restricted data stored within global variables and objects.
nvd
CVE-2003-0284P4HIGHCVSS 7.5v5.02003-06-16
CVE-2003-0284 [HIGH] CVE-2003-0284: Adobe Acrobat 5 does not properly validate JavaScript in PDF files, which allows remote attackers to
Adobe Acrobat 5 does not properly validate JavaScript in PDF files, which allows remote attackers to write arbitrary files into the Plug-ins folder that spread to other PDF documents, as demonstrated by the W32.Yourde virus.
nvd
CVE-2007-0045P4MEDIUMCVSS 4.3≤ 7.0.8v7.0+8 more2007-01-03
CVE-2007-0045 [MEDIUM] CWE-79 CVE-2007-0045: Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers
nvd
CVE-2015-6700P4MEDIUMCVSS 5.0≥ 10.0, ≤ 10.1.15≥ 11.0.0, ≤ 11.0.122015-10-14
CVE-2015-6700 [MEDIUM] CVE-2015-6700: The setBackground function in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13,
The setBackground function in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to obtain sensitive information from process memory via invalid arguments, a different vulnerabil
nvd
CVE-2015-4449P4MEDIUMCVSS 5.0≥ 10.0, ≤ 10.1.14≥ 11.0.0, ≤ 11.0.112015-07-15
CVE-2015-4449 [MEDIUM] CVE-2015-4449: Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than
nvd
CVE-2014-8450P4MEDIUMCVSS 5.0≥ 10.0, < 10.1.15≥ 11.0.0, < 11.0.122015-07-15
CVE-2014-8450 [MEDIUM] CWE-200 CVE-2014-8450: Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerabili
nvd
CVE-2015-5089P4MEDIUMCVSS 5.0≥ 10.0, ≤ 10.1.14≥ 11.0.0, ≤ 11.0.112015-07-15
CVE-2015-5089 [MEDIUM] CVE-2015-5089: Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than
nvd
CVE-2015-5088P4MEDIUMCVSS 5.0≥ 10.0, ≤ 10.1.14≥ 11.0.0, ≤ 11.0.112015-07-15
CVE-2015-5088 [MEDIUM] CVE-2015-5088: Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than
nvd
CVE-2015-4450P4MEDIUMCVSS 5.0≥ 10.0, < 10.1.15≥ 11.0.0, < 11.0.122015-07-15
CVE-2015-4450 [MEDIUM] CVE-2015-4450: Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than
nvd
CVE-2015-5092P4MEDIUMCVSS 5.0≥ 10.0, < 10.1.15≥ 11.0.0, < 11.0.122015-07-15
CVE-2015-5092 [MEDIUM] CVE-2015-5092: Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than
nvd
CVE-2022-38437P4MEDIUMCVSS 5.5≥ 20.001.30005, < 20.005.304072022-10-14
CVE-2022-38437 [MEDIUM] CWE-416 CVE-2022-38437: Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected
Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a m
nvd
CVE-2023-38243P4MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.005.30516.10516≥ 20.001.30005, < 20.005.30514.105142023-08-10
CVE-2023-38243 [MEDIUM] CWE-416 CVE-2023-38243: Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use-After-Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a m
nvd