cbcvebase.

Adobe Acrobat Dc vulnerabilities

1,798 known vulnerabilities affecting adobe/acrobat_dc.

Total CVEs
1,798
CISA KEV
7
actively exploited
Public exploits
30
Exploited in wild
15
Severity breakdown
CRITICAL449HIGH859MEDIUM456LOW34

Vulnerabilities

Page 86 of 90
CVE-2021-39852P4MEDIUMCVSS 5.5≥ 15.008.20082, ≤ 21.005.20058≥ 15.008.20082, ≤ 21.005.200602021-09-29
CVE-2021-39852 [MEDIUM] CWE-476 CVE-2021-39852: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requi
nvd
CVE-2021-39851P4MEDIUMCVSS 5.5≥ 15.008.20082, ≤ 21.005.20058≥ 15.008.20082, ≤ 21.005.200602021-09-29
CVE-2021-39851 [MEDIUM] CWE-476 CVE-2021-39851: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requi
nvd
CVE-2021-39849P4MEDIUMCVSS 5.5≥ 15.008.20082, ≤ 21.005.20058≥ 15.008.20082, ≤ 21.005.200602021-09-29
CVE-2021-39849 [MEDIUM] CWE-476 CVE-2021-39849: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requi
nvd
CVE-2021-39850P4MEDIUMCVSS 5.5≥ 15.008.20082, ≤ 21.005.20058≥ 15.008.20082, ≤ 21.005.200602021-09-29
CVE-2021-39850 [MEDIUM] CWE-476 CVE-2021-39850: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requi
nvd
CVE-2021-35985P4MEDIUMCVSS 5.5≥ 15.008.20082, ≤ 21.005.20054≥ 17.011.30059, ≤ 17.011.30197+1 more2021-08-20
CVE-2021-35985 [MEDIUM] CWE-476 CVE-2021-35985: Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requi
nvd
CVE-2015-6702P4MEDIUMCVSS 4.3≥ 15.006.30060, < 15.006.30094≥ 15.008.20082, < 15.009.200692015-10-14
CVE-2015-6702 [MEDIUM] CVE-2015-6702: The createSquareMesh function in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.1 The createSquareMesh function in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to obtain sensitive information from process memory via invalid arguments, a different vulner
nvd
CVE-2015-6699P4MEDIUMCVSS 4.3≥ 15.006.30060, < 15.006.30094≥ 15.008.20082, < 15.009.200692015-10-14
CVE-2015-6699 [MEDIUM] CVE-2015-6699: The addForegroundSprite function in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11. The addForegroundSprite function in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to obtain sensitive information from process memory via invalid arguments, a different vul
nvd
CVE-2015-6703P4MEDIUMCVSS 4.3≥ 15.006.30060, < 15.006.30094≥ 15.008.20082, < 15.009.200692015-10-14
CVE-2015-6703 [MEDIUM] CVE-2015-6703: The loadFlashMovie function in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, The loadFlashMovie function in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to obtain sensitive information from process memory via invalid arguments, a different vulnerab
nvd
CVE-2021-39859P4MEDIUMCVSS 5.5≥ 15.007.20033, ≤ 21.005.20060≥ 15.007.20033, ≤ 21.005.200582023-09-06
CVE-2021-39859 [MEDIUM] CWE-416 CVE-2021-39859: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction
nvd
CVE-2023-38245P4MEDIUMCVSS 5.5≥ 15.008.20082, < 23.003.202692023-08-10
CVE-2023-38245 [MEDIUM] CWE-200 CVE-2023-38245: Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obtain NTLMv2 credentials. Exploitation of this issue requires user interaction in that a victim must open a maliciously crafted Microsoft Of
nvd
CVE-2021-40723P4MEDIUMCVSS 5.5fixed in 21.001.201352023-09-07
CVE-2021-40723 [MEDIUM] CWE-125 CVE-2021-40723: Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2 Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires us
nvd
CVE-2019-7819P4MEDIUMCVSS 5.5≥ 15.000.00000, ≤ 15.006.30482≥ 17.000.00000, ≤ 17.011.30127+1 more2023-09-11
CVE-2019-7819 [MEDIUM] CWE-125 CVE-2019-7819: Adobe Acrobat Reader versions 2019.010.20098 and earlier are affected by an out-of-bounds read vulne Adobe Acrobat Reader versions 2019.010.20098 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-43579P4MEDIUMCVSS 5.5≥ 15.008.20082, < 25.001.20531≥ 15.008.20082, < 25.001.205292025-06-10
CVE-2025-43579 [MEDIUM] CWE-200 CVE-2025-43579: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an Info Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an Information Exposure vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain unauthorized access to sensitive information. Exploitation of this issue does not require user interaction.
nvd
CVE-2026-27221P4MEDIUMCVSS 5.5fixed in 25.001.212882026-03-10
CVE-2026-27221 [MEDIUM] CWE-295 CVE-2026-27221: Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Impr Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to spoof the identity of a signer. Exploitation of this issue requires user interaction.
nvd
CVE-2021-21034P4MEDIUMCVSS 4.3≤ 20.013.200742021-02-11
CVE-2021-21034 [MEDIUM] CWE-125 CVE-2021-21034: Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2 Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to locally elevate privileges in the context of the current user. Exploitation of this issue requires user i
nvd
CVE-2018-15949P4MEDIUMCVSS 5.5≥ 15.006.30060, ≤ 15.006.30452≥ 15.008.20082, ≤ 18.011.20063+1 more2018-10-12
CVE-2018-15949 [MEDIUM] CWE-125 CVE-2018-15949: Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.0 Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2018-15968P4MEDIUMCVSS 5.5≥ 15.006.30060, ≤ 15.006.30452≥ 15.008.20082, ≤ 18.011.20063+1 more2018-10-12
CVE-2018-15968 [MEDIUM] CWE-125 CVE-2018-15968: Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.0 Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2018-15950P4MEDIUMCVSS 5.5≥ 15.006.30060, ≤ 15.006.30452≥ 15.008.20082, ≤ 18.011.20063+1 more2018-10-12
CVE-2018-15950 [MEDIUM] CWE-125 CVE-2018-15950: Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.0 Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2018-12834P4MEDIUMCVSS 5.5≥ 15.006.30060, ≤ 15.006.30452≥ 15.008.20082, ≤ 18.011.20063+1 more2018-10-12
CVE-2018-12834 [MEDIUM] CWE-125 CVE-2018-12834: Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.0 Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2018-15984P4MEDIUMCVSS 5.5≥ 15.006.30060, ≤ 15.006.30457≥ 15.008.20082, ≤ 19.008.20081+4 more2019-01-18
CVE-2018-15984 [MEDIUM] CWE-125 CVE-2018-15984: Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.2 Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure
nvd
Adobe Acrobat Dc vulnerabilities | cvebase