cbcvebase.

Adobe Acrobat Reader vulnerabilities

1,132 known vulnerabilities affecting adobe/acrobat_reader.

Total CVEs
1,132
CISA KEV
22
actively exploited
Public exploits
46
Exploited in wild
42
Severity breakdown
CRITICAL350HIGH432MEDIUM321LOW29

Vulnerabilities

Page 19 of 57
CVE-2010-3626P3CRITICALCVSS 9.3v8.0v8.1+22 more2010-10-06
CVE-2010-3626 [CRITICAL] CVE-2010-3626: Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Window Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execute arbitrary code via a crafted font, a different vulnerability than CVE-2010-2889.
nvd
CVE-2016-0940P3CRITICALCVSS 9.8≤ 11.0.13v11.0.0+12 more2016-01-14
CVE-2016-0940 [CRITICAL] CVE-2016-0940: Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0932, CVE-2016-0934, CVE-2016-0937,
nvd
CVE-2016-0936P3HIGHCVSS 8.8≤ 11.0.13v11.0.0+12 more2016-01-14
CVE-2016-0936 [HIGH] CVE-2016-0936: Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JPEG 2000 data, a different vulnerability than CVE-2016-0931, CVE-2016-0933,
nvd
CVE-2010-3624P3CRITICALCVSS 9.3v8.0v8.1+22 more2010-10-06
CVE-2010-3624 [CRITICAL] CWE-20 CVE-2010-3624: Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.5 and 9.x before 9.4 on Mac OS Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.5 and 9.x before 9.4 on Mac OS X allows attackers to execute arbitrary code via a crafted image.
nvd
CVE-2009-1855P3CRITICALCVSS 9.3v7.0v7.0.1+20 more2009-06-11
CVE-2009-1855 [CRITICAL] CWE-119 CVE-2009-1855: Stack-based buffer overflow in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat Stack-based buffer overflow in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow attackers to execute arbitrary code via a PDF file containing a malformed U3D model file with a crafted extension block.
nvd
CVE-2011-0586P3CRITICALCVSS 9.3v8.0v8.1+25 more2011-02-10
CVE-2011-0586 [CRITICAL] CWE-20 CVE-2011-0586: Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and M Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X do not properly validate unspecified input data, which allows attackers to execute arbitrary code via unknown vectors.
nvd
CVE-2024-39423P3HIGHCVSS 7.8≥ 20.001.3005, < 20.005.30655≤ 24.001.301232024-08-14
CVE-2024-39423 [HIGH] CWE-787 CVE-2024-39423: Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affec Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2010-2888P3CRITICALCVSS 9.3v8.0v8.1+22 more2010-10-06
CVE-2010-2888 [CRITICAL] CWE-20 CVE-2010-2888: Multiple unspecified vulnerabilities in an ActiveX control in Adobe Reader and Acrobat 8.x before 8. Multiple unspecified vulnerabilities in an ActiveX control in Adobe Reader and Acrobat 8.x before 8.2.5 and 9.x before 9.4 on Windows allow attackers to execute arbitrary code via unknown vectors.
nvd
CVE-2011-2438P3CRITICALCVSS 9.3v8.0v8.1+34 more2011-09-15
CVE-2011-2438 [CRITICAL] CWE-119 CVE-2011-2438: Multiple stack-based buffer overflows in the image-parsing library in Adobe Reader and Acrobat 8.x b Multiple stack-based buffer overflows in the image-parsing library in Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allow attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2017-11251P3HIGHCVSS 8.8≥ 17.011.00000, ≤ 17.011.300662017-08-11
CVE-2017-11251 [HIGH] CWE-119 CVE-2017-11251: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the JPEG 2000 parsing module. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-0941P3HIGHCVSS 8.8≤ 11.0.13v11.0.0+12 more2016-01-14
CVE-2016-0941 [HIGH] CVE-2016-0941: Use-after-free vulnerability in the Search object implementation in Adobe Reader and Acrobat before Use-after-free vulnerability in the Search object implementation in Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-093
nvd
CVE-2016-0932P3HIGHCVSS 8.8≤ 11.0.13v11.0.0+12 more2016-01-14
CVE-2016-0932 [HIGH] CVE-2016-0932: Use-after-free vulnerability in the Doc object implementation in Adobe Reader and Acrobat before 11. Use-after-free vulnerability in the Doc object implementation in Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0934,
nvd
CVE-2017-16377P3HIGHCVSS 8.8≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16377 [HIGH] CWE-824 CVE-2017-16377: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is due to a computation that accesses a pointer that has not been initialized in the main DLL. In this case, a computation defines a rea
nvd
CVE-2017-16378P3HIGHCVSS 8.8≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16378 [HIGH] CWE-824 CVE-2017-16378: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is due to a computation that accesses a pointer that has not been initialized; the computation occurs during internal AST thread manipul
nvd
CVE-2017-16375P3HIGHCVSS 8.8≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16375 [HIGH] CWE-119 CVE-2017-16375: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This issue is due to an untrusted pointer dereference in the JavaSscript API engine. In this scenario, the JavaScript input is crafted in way that the comp
nvd
CVE-2017-16362P3HIGHCVSS 8.8≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16362 [HIGH] CWE-125 CVE-2017-16362: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of an out of bounds read vulnerability in the MakeAccesible plugin, when handling font data. It causes an out of bounds m
nvd
CVE-2016-0937P3HIGHCVSS 8.8≤ 11.0.13v11.0.0+12 more2016-01-14
CVE-2016-0937 [HIGH] CVE-2016-0937: Use-after-free vulnerability in the OCG object implementation in Adobe Reader and Acrobat before 11. Use-after-free vulnerability in the OCG object implementation in Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0932,
nvd
CVE-2017-11237P3HIGHCVSS 8.8≥ 17.011.00000, ≤ 17.011.300662017-08-11
CVE-2017-11237 [HIGH] CWE-119 CVE-2017-11237: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the font parsing module. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2009-1061P3CRITICALCVSS 9.3≥ 7.0, < 7.1.1≥ 8.0, < 8.1.4+1 more2009-03-25
CVE-2009-1061 [CRITICAL] CVE-2009-1061: Unspecified vulnerability in Adobe Acrobat Reader 9 before 9.1, 8 before 8.1.4, and 7 before 7.1.1 m Unspecified vulnerability in Adobe Acrobat Reader 9 before 9.1, 8 before 8.1.4, and 7 before 7.1.1 might allow remote attackers to execute arbitrary code via unknown attack vectors related to JBIG2 and "input validation," a different vulnerability than CVE-2009-0193 and CVE-2009-1062.
nvd
CVE-2012-1530P3CRITICALCVSS 10.0v9.0v9.1+30 more2013-01-10
CVE-2012-1530 [CRITICAL] CWE-119 CVE-2012-1530: Heap-based buffer overflow in the XSLT engine in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x bef Heap-based buffer overflow in the XSLT engine in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a PDF file containing an XSL file that triggers memory corruption when the lang function processes XML data with a craft
nvd