cbcvebase.

Adobe Acrobat Dc vulnerabilities

1,798 known vulnerabilities affecting adobe/acrobat_dc.

Total CVEs
1,798
CISA KEV
7
actively exploited
Public exploits
30
Exploited in wild
15
Severity breakdown
CRITICAL449HIGH859MEDIUM456LOW34

Vulnerabilities

Page 66 of 90
CVE-2020-24428P3HIGHCVSS 7.7≤ 17.011.30175≤ 20.012.200482020-11-05
CVE-2020-24428 [HIGH] CWE-367 CVE-2020-24428: Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) for macOS are affected by a time-of-check time-of-use (TOCTOU) race condition vulnerability that could result in local privilege escalation. Exploitation of this issue requires user interaction in that a victim must open a malicious f
nvd
CVE-2022-35672P3HIGHCVSS 7.8≥ 15.008.20082, ≤ 22.001.200852022-07-27
CVE-2022-35672 [HIGH] CWE-125 CVE-2022-35672: Adobe Acrobat Reader version 22.001.20085 (and earlier), 20.005.30314 (and earlier) and 17.012.30205 Adobe Acrobat Reader version 22.001.20085 (and earlier), 20.005.30314 (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of t
nvd
CVE-2026-47937P3HIGHCVSS 7.7≥ 15.008.20082, < 26.001.216622026-06-09
CVE-2026-47937 [HIGH] CWE-427 CVE-2026-47937: Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Searc Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interact
nvd
CVE-2020-29075P3MEDIUMCVSS 6.5≥ 15.008.20082, ≤ 20.013.200662021-02-23
CVE-2020-29075 [MEDIUM] CWE-20 CVE-2020-29075: Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) are affected by an information exposure vulnerability, that could enable an attacker to get a DNS interaction and track if the user has opened or closed a PDF file when loaded from the filesystem without a prompt. User interaction is
nvd
CVE-2018-15966P3HIGHCVSS 7.8≥ 15.006.30060, ≤ 15.006.30452≥ 15.008.20082, ≤ 18.011.20063+1 more2018-10-12
CVE-2018-15966 [HIGH] CVE-2018-15966: Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.0 Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a security bypass vulnerability. Successful exploitation could lead to privilege escalation.
nvd
CVE-2015-7619P3MEDIUMCVSS 6.8≥ 15.006.30060, < 15.006.30094≥ 15.008.20082, < 15.009.200692015-10-14
CVE-2015-7619 [MEDIUM] CVE-2015-7619: The ANShareFile2 method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acr The ANShareFile2 method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability
nvd
CVE-2015-6722P3MEDIUMCVSS 6.8≥ 15.006.30060, < 15.006.30094≥ 15.008.20082, < 15.009.200692015-10-14
CVE-2015-6722 [MEDIUM] CVE-2015-6722: The CBSharedReviewStatusDialog method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x befor The CBSharedReviewStatusDialog method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different
nvd
CVE-2015-6714P3MEDIUMCVSS 6.8≥ 15.006.30060, < 15.006.30094≥ 15.008.20082, < 15.009.200692015-10-14
CVE-2015-6714 [MEDIUM] CVE-2015-6714: The Function bind implementation in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11. The Function bind implementation in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulne
nvd
CVE-2015-6711P3MEDIUMCVSS 6.8≥ 15.006.30060, < 15.006.30094≥ 15.008.20082, < 15.009.200692015-10-14
CVE-2015-6711 [MEDIUM] CVE-2015-6711: The DoIdentityDialog method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, The DoIdentityDialog method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerabil
nvd
CVE-2015-6709P3MEDIUMCVSS 6.8≥ 15.006.30060, < 15.006.30094≥ 15.008.20082, < 15.009.200692015-10-14
CVE-2015-6709 [MEDIUM] CVE-2015-6709: The CBBBRInvite method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acro The CBBBRInvite method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability t
nvd
CVE-2015-6717P3MEDIUMCVSS 6.8≥ 15.006.30060, < 15.006.30094≥ 15.008.20082, < 15.009.200692015-10-14
CVE-2015-6717 [MEDIUM] CVE-2015-6717: The DynamicAnnotStore method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13 The DynamicAnnotStore method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerabi
nvd
CVE-2015-7616P3MEDIUMCVSS 6.8≥ 15.006.30060, < 15.006.30094≥ 15.008.20082, < 15.009.200692015-10-14
CVE-2015-7616 [MEDIUM] CVE-2015-7616: The ANVerifyComments method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, The ANVerifyComments method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerabil
nvd
CVE-2015-7623P3MEDIUMCVSS 6.8≥ 15.006.30060, < 15.006.30094≥ 15.008.20082, < 15.009.200692015-10-14
CVE-2015-7623 [MEDIUM] CVE-2015-7623: The ANAuthenticateResource method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11 The ANAuthenticateResource method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vuln
nvd
CVE-2015-6719P3MEDIUMCVSS 6.8≥ 15.006.30060, < 15.006.30094≥ 15.008.20082, < 15.009.200692015-10-14
CVE-2015-6719 [MEDIUM] CVE-2015-6719: The CBSharedReviewCloseDialog method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before The CBSharedReviewCloseDialog method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different v
nvd
CVE-2015-6710P3MEDIUMCVSS 6.8≥ 15.006.30060, < 15.006.30094≥ 15.008.20082, < 15.009.200692015-10-14
CVE-2015-6710 [MEDIUM] CVE-2015-6710: The CBBBRInit method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acroba The CBBBRInit method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability tha
nvd
CVE-2015-6708P3MEDIUMCVSS 6.8≥ 15.006.30060, < 15.006.30094≥ 15.008.20082, < 15.009.200692015-10-14
CVE-2015-6708 [MEDIUM] CVE-2015-6708: The ANStartApproval method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, The ANStartApproval method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerabilit
nvd
CVE-2015-6724P3MEDIUMCVSS 6.8≥ 15.006.30060, < 15.006.30094≥ 15.008.20082, < 15.009.200692015-10-14
CVE-2015-6724 [MEDIUM] CVE-2015-6724: The ANSendForApproval method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13 The ANSendForApproval method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerabi
nvd
CVE-2015-6707P3MEDIUMCVSS 6.8≥ 15.006.30060, < 15.006.30094≥ 15.008.20082, < 15.009.200692015-10-14
CVE-2015-6707 [MEDIUM] CVE-2015-6707: The ANSendForReview method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, The ANSendForReview method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerabilit
nvd
CVE-2015-6716P3MEDIUMCVSS 6.8≥ 15.006.30060, < 15.006.30094≥ 15.008.20082, < 15.009.200692015-10-14
CVE-2015-6716 [MEDIUM] CVE-2015-6716: The ANSendForFormDistribution method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before The ANSendForFormDistribution method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different v
nvd
CVE-2015-6721P3MEDIUMCVSS 6.8≥ 15.006.30060, < 15.006.30094≥ 15.008.20082, < 15.009.200692015-10-14
CVE-2015-6721 [MEDIUM] CVE-2015-6721: The CBSharedReviewSecurityDialog method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x bef The CBSharedReviewSecurityDialog method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a differen
nvd
Adobe Acrobat Dc vulnerabilities | cvebase