Adobe Acrobat Reader vulnerabilities
1,132 known vulnerabilities affecting adobe/acrobat_reader.
Total CVEs
1,132
CISA KEV
22
actively exploited
Public exploits
46
Exploited in wild
42
Severity breakdown
CRITICAL350HIGH432MEDIUM321LOW29
Vulnerabilities
Page 1 of 57
CVE-2011-2462P1CRITICALCVSS 9.8KEVPoC≤ 10.1.1≥ 9.0, ≤ 9.4.62011-12-07
CVE-2011-2462 [CRITICAL] CWE-787 CVE-2011-2462: Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Win
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.
nvd
CVE-2009-0927P1HIGHCVSS 8.8KEVPoC≥ 7.0, < 7.1.1≥ 8.0, < 8.1.3+1 more2009-03-19
CVE-2009-0927 [HIGH] CVE-2009-0927: Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 b
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab object, a different vulnerability than CVE-2009-0658.
nvd
CVE-2008-2992P1HIGHCVSS 7.8KEVPoCRansomware≤ 8.1.22008-11-04
CVE-2008-2992 [HIGH] CVE-2008-2992: Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argument, a related issue to CVE-2008-1104.
nvd
CVE-2011-0611P1HIGHCVSS 8.8KEVPoC≥ 9.0, < 9.4.4≥ 10.0, ≤ 10.0.1+1 more2011-04-13
CVE-2011-0611 [HIGH] CWE-843 CVE-2011-0611: Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and e
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.
nvd
CVE-2013-3346P1CRITICALCVSS 9.8KEVPoC≥ 9.0, < 9.5.5≥ 10.0, < 10.1.7+1 more2013-08-30
CVE-2013-3346 [CRITICAL] CVE-2013-3346: Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attacke
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2
nvd
CVE-2021-21017P1HIGHCVSS 8.8KEVPoC≥ 17.0, ≤ 17.011.30188≥ 20.0, ≤ 20.001.300183+1 more2021-02-11
CVE-2021-21017 [HIGH] CWE-122 CVE-2021-21017: Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requ
nvd
CVE-2013-2729P1CRITICALCVSS 9.8KEVPoCRansomware≥ 9.0, < 9.5.5≥ 10.0, < 10.1.7+1 more2013-05-16
CVE-2013-2729 [CRITICAL] CVE-2013-2729: Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 1
Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727.
nvd
CVE-2013-0640P1HIGHCVSS 7.8KEVPoC≥ 10.0, < 10.1.6≥ 11.0, < 11.0.02+1 more2013-02-14
CVE-2013-0640 [HIGH] CWE-787 CVE-2013-0640: Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as exploited in the wild in February 2013.
nvd
CVE-2009-3459P1HIGHCVSS 8.8KEVPoC≥ 7.0, < 7.1.4≥ 8.0, < 8.1.7+1 more2009-10-13
CVE-2009-3459 [HIGH] CWE-119 CVE-2009-3459: Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x b
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.
nvd
CVE-2009-4324P1HIGHCVSS 7.8KEVPoC≥ 8.0, < 8.2≥ 9.0, < 9.32009-12-15
CVE-2009-4324 [HIGH] CWE-416 CVE-2009-4324: Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.
nvd
CVE-2010-0188P1HIGHCVSS 7.8KEVPoCRansomware≥ 8.0, < 8.2.1≥ 9.0, < 9.3.12010-02-22
CVE-2010-0188 [HIGH] CVE-2010-0188: Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows a
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2010-2883P1HIGHCVSS 7.3KEVPoC≥ 8.0, < 8.2.5≥ 9.0, < 9.42010-09-09
CVE-2010-2883 [HIGH] CWE-787 CVE-2010-2883: Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x befo
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild
nvd
CVE-2007-5659P1HIGHCVSS 7.8KEVPoCfixed in 8.1.22008-02-12
CVE-2007-5659 [HIGH] CWE-120 CVE-2007-5659: Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to ex
Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655.
nvd
CVE-2011-0609P1HIGHCVSS 7.8KEVPoC≥ 9.0, ≤ 9.4.2v10.0+1 more2011-03-15
CVE-2011-0609 [HIGH] CVE-2011-0609: Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux,
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary co
nvd
CVE-2023-21608P1HIGHCVSS 7.8KEVPoC≥ 20.001.30005, ≤ 20.005.30418≥ unspecified, ≤ 20.005.304182023-01-18
CVE-2023-21608 [HIGH] CWE-416 CVE-2023-21608: Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.3041
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-34621P1HIGHCVSS 8.6KEVPoC≤ 26.001.213672026-04-11
CVE-2026-34621 [HIGH] CWE-1321 CVE-2026-34621: Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Control
Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a ma
nvd
CVE-2021-28550P1HIGHCVSS 8.8KEV≥ 17.011.30059, ≤ 17.011.30194≥ 20.001.30005, ≤ 20.001.30020+1 more2021-09-02
CVE-2021-28550 [HIGH] CWE-416 CVE-2021-28550: Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user in
nvd
CVE-2014-0546P1CRITICALCVSS 9.8KEV≥ 10.0, < 10.1.11≥ 11.0, < 11.0.082014-08-12
CVE-2014-0546 [CRITICAL] CVE-2014-0546: Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to b
Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via unspecified vectors.
nvd
CVE-2013-0641P1HIGHCVSS 7.8KEV≥ 10.0, < 10.1.6≥ 11.0, < 11.0.02+1 more2013-02-14
CVE-2013-0641 [HIGH] CWE-120 CVE-2013-0641: Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary code via a crafted PDF document, as exploited in the wild in February 2013.
nvd
CVE-2023-26369P1HIGHCVSS 7.8KEV≥ 20.001.3005, < 20.005.30524≤ 20.005.305142023-09-13
CVE-2023-26369 [HIGH] CWE-787 CVE-2023-26369: Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and
Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
1 / 57Next →