cbcvebase.

Adobe Acrobat vulnerabilities

1,379 known vulnerabilities affecting adobe/acrobat.

Total CVEs
1,379
CISA KEV
24
actively exploited
Public exploits
46
Exploited in wild
41
Severity breakdown
CRITICAL538HIGH495MEDIUM320LOW26

Vulnerabilities

Page 68 of 69
CVE-2025-47111P4MEDIUMCVSS 5.5≥ 20.0, < 20.005.30774≥ 24.0.0, < 24.001.302542025-06-10
CVE-2025-47111 [MEDIUM] CWE-476 CVE-2025-47111: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a NULL Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing a disruption in service. Exploitation of this issue requires user interaction in that a v
nvd
CVE-2017-3022P4LOWCVSS 3.3≤ 11.0.192017-04-12
CVE-2017-3022 [LOW] CWE-125 CVE-2017-3022: Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlie Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability when parsing the header of a JPEG 2000 file.
nvd
CVE-2009-2979P4MEDIUMCVSS 4.3≤ 9.1.3v7.0+22 more2009-10-19
CVE-2009-2979 [MEDIUM] CVE-2009-2979: Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 do not pro Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 do not properly perform XMP-XML entity expansion, which allows remote attackers to cause a denial of service via a crafted document.
nvd
CVE-2010-0190P4MEDIUMCVSS 4.3v9.0v9.1+17 more2010-04-14
CVE-2010-0190 [MEDIUM] CWE-79 CVE-2010-0190: Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x befor Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2022-28269P4LOWCVSS 3.3≥ 17.011.30059, ≤ 17.012.30205≥ 20.001.30005, ≤ 20.005.30314+1 more2022-05-11
CVE-2022-28269 [LOW] CWE-416 CVE-2022-28269: Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 ( Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of Annotation objects that could result in a memory leak in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a m
nvd
CVE-2020-24431P4MEDIUMCVSS 4.4≤ 20.001.300052020-11-05
CVE-2020-24431 [MEDIUM] CWE-285 CVE-2020-24431: Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) for macOS are affected by a security feature bypass that could result in dynamic library code injection by the Adobe Reader process. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2021-39844P4LOWCVSS 3.3≥ 20.001.30005, ≤ 20.004.30006≥ 17.011.30059, ≤ 17.011.301992021-09-29
CVE-2021-39844 [LOW] CWE-125 CVE-2021-39844: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal
nvd
CVE-2009-2992P4MEDIUMCVSS 4.3≤ 9.1.3v7.0+22 more2009-10-19
CVE-2009-2992 [MEDIUM] CWE-20 CVE-2009-2992: An unspecified ActiveX control in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and pos An unspecified ActiveX control in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 does not properly validate input, which allows attackers to cause a denial of service via unknown vectors.
nvd
CVE-2009-2995P4MEDIUMCVSS 4.3≤ 9.1.3v7.0+22 more2009-10-19
CVE-2009-2995 [MEDIUM] CWE-189 CVE-2009-2995: Integer overflow in Adobe Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows atta Integer overflow in Adobe Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows attackers to cause a denial of service via unspecified vectors.
nvd
CVE-2009-2988P4MEDIUMCVSS 4.3v7.0v7.0.1+22 more2009-10-19
CVE-2009-2988 [MEDIUM] CWE-20 CVE-2009-2988: Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly vali Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which allows attackers to cause a denial of service via unspecified vectors.
nvd
CVE-2014-5315P4MEDIUMCVSS 4.3≤ 9.5.2v9.0+20 more2014-09-26
CVE-2014-5315 [MEDIUM] CWE-79 CVE-2014-5315: Cross-site scripting (XSS) vulnerability in the Help page in Adobe Acrobat 9.5.2 and earlier and Col Cross-site scripting (XSS) vulnerability in the Help page in Adobe Acrobat 9.5.2 and earlier and ColdFusion 8.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2006-0525P4MEDIUMCVSS 4.6v3.0v3.1+16 more2006-02-02
CVE-2006-0525 [MEDIUM] CWE-264 CVE-2006-0525: Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center, install a large number of .EXE and .DLL files with write-access permission for the Everyone group, which allows local users to gain privileges via Trojan horse programs.
nvd
CVE-2021-40729P4LOWCVSS 3.3≥ 20.001.30005, ≤ 20.004.30015≥ 17.011.30158, ≤ 17.011.302022021-10-15
CVE-2021-40729 [LOW] CWE-125 CVE-2021-40729: Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 (and earlier), and 17.011.30202 (and earlier) is affected by a out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this iss
nvd
CVE-2025-54255P4MEDIUMCVSS 4.0≥ 24.0.0, < 24.001.30264≥ 20.001.30002, < 20.005.30793+1 more2025-09-09
CVE-2025-54255 [MEDIUM] CWE-657 CVE-2025-54255: Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Viola Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Violation of Secure Design Principles vulnerability that could result in a security feature bypass impacting integrity. An attacker does not have to be authenticated. Exploitation of this issue does not require user interaction, and scope is unchanged.
nvd
CVE-2002-0030P4MEDIUMCVSS 4.6v4.0v4.0.5+4 more2003-04-02
CVE-2002-0030 [MEDIUM] CVE-2002-0030: The digital signature mechanism for the Adobe Acrobat PDF viewer only verifies the PE header of exec The digital signature mechanism for the Adobe Acrobat PDF viewer only verifies the PE header of executable code for a plug-in, which can allow attackers to execute arbitrary code in certified mode by making the plug-in appear to be signed by Adobe.
nvd
CVE-2020-24438P4LOWCVSS 3.3≤ 20.001.300052020-11-05
CVE-2020-24438 [LOW] CWE-416 CVE-2020-24438: Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a use-after-free vulnerability that could result in a memory address leak. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2023-29299P4MEDIUMCVSS 4.7≥ 20.001.30005, ≤ 20.005.30516.10516≥ 20.001.30005, < 20.005.30514.105142023-08-10
CVE-2023-29299 [MEDIUM] CWE-426 CVE-2023-29299: Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Untrusted Search Path vulnerability that could lead to Application denial-of-service. An attacker could leverage this vulnerability if the default PowerShell Set-ExecutionPolicy is set to Unrestricted, making the attack complexity high. Exploit
nvd
CVE-2021-40730P4LOWCVSS 3.3≥ 20.001.30005, ≤ 20.004.30015≥ 17.011.30158, ≤ 17.011.302022021-10-15
CVE-2021-40730 [LOW] CWE-416 CVE-2021-40730: Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 (and earlier), and 17.011.30202 (and earlier) is affected by a use-after-free that allow a remote attacker to disclose sensitive information on affected installations of of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerabil
nvd
CVE-2021-39858P4LOWCVSS 3.3≥ 20.001.30005, ≤ 20.004.300062021-09-29
CVE-2021-39858 [LOW] CWE-125 CVE-2021-39858: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal
nvd
CVE-2009-2987P4MEDIUMCVSS 4.3≤ 9.1.3v7.0+22 more2009-10-19
CVE-2009-2987 [MEDIUM] CVE-2009-2987: Unspecified vulnerability in an ActiveX control in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x be Unspecified vulnerability in an ActiveX control in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 on Windows allows remote attackers to cause a denial of service via unknown vectors.
nvd
Adobe Acrobat vulnerabilities | cvebase