Adobe Acrobat Reader vulnerabilities
1,132 known vulnerabilities affecting adobe/acrobat_reader.
Total CVEs
1,132
CISA KEV
22
actively exploited
Public exploits
46
Exploited in wild
42
Severity breakdown
CRITICAL350HIGH432MEDIUM321LOW29
Vulnerabilities
Page 2 of 57
CVE-2008-0655P2HIGHCVSS 8.8KEVfixed in 8.1.22008-02-07
CVE-2008-0655 [HIGH] CWE-200 CVE-2008-0655: Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact an
Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.
nvd
CVE-2009-1862P2HIGHCVSS 7.8KEV≥ 9.0, ≤ 9.1.22009-07-23
CVE-2009-1862 [HIGH] CWE-787 CVE-2009-1862: Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x
Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exp
nvd
CVE-2009-0658P1HIGHCVSS 7.8ExploitedPoC≥ 7.0, ≤ 7.1.1≥ 8.0, ≤ 8.1.4+1 more2009-02-20
CVE-2009-0658 [HIGH] CWE-119 CVE-2009-0658: Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attacker
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream, as exploited in the wild in February 2009 by Trojan.Pidief.E.
nvd
CVE-2010-3654P2CRITICALCVSS 9.3ExploitedPoCv9.0v9.1+10 more2010-10-29
CVE-2010-3654 [CRITICAL] CWE-119 CVE-2010-3654: Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Sol
Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and applica
nvd
CVE-2010-1240P2CRITICALCVSS 9.3ExploitedPoCv9.3.12010-04-05
CVE-2010-1240 [CRITICAL] CWE-264 CVE-2010-1240: Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not rest
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in the Launch File warning dialog, which makes it easier for remote attackers to trick users into executing an arbitrary local program that was specified in a PDF document, as demonstrated by a text field that claim
nvd
CVE-2009-2990P2CRITICALCVSS 9.3ExploitedPoC≤ 9.1.3v7.0+24 more2009-10-19
CVE-2009-2990 [CRITICAL] CWE-189 CVE-2009-2990: Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x thr
Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2010-2862P2CRITICALCVSS 9.3ExploitedPoCv8.2.3v9.3.32010-08-05
CVE-2010-2862 [CRITICAL] CWE-189 CVE-2010-2862: Integer overflow in CoolType.dll in Adobe Reader 8.2.3 and 9.3.3, and Acrobat 9.3.3, allows remote a
Integer overflow in CoolType.dll in Adobe Reader 8.2.3 and 9.3.3, and Acrobat 9.3.3, allows remote attackers to execute arbitrary code via a TrueType font with a large maxCompositePoints value in a Maximum Profile (maxp) table.
nvd
CVE-2009-1492P2CRITICALCVSS 9.3ExploitedPoC≥ 7.0, ≤ 7.1.1≥ 8.0, ≤ 8.1.4+1 more2009-04-30
CVE-2009-1492 [CRITICAL] CWE-399 CVE-2009-1492: The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and ea
The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments
nvd
CVE-2006-6027P2CRITICALCVSS 9.3ExploitedPoCv7.0v7.0.1+7 more2006-11-21
CVE-2006-6027 [CRITICAL] CVE-2006-6027: Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of s
Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the LoadFile method in an AcroPDF ActiveX control.
nvd
CVE-2024-41869P2HIGHCVSS 7.8Exploitedfixed in 20.005.30680≤ 24.003.200542024-09-13
CVE-2024-41869 [HIGH] CWE-416 CVE-2024-41869: Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affec
Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2010-2884P2CRITICALCVSS 9.3Exploited≤ 9.3.4v3.0+54 more2010-09-15
CVE-2010-2884 [CRITICAL] CVE-2010-2884: Adobe Flash Player 10.1.82.76 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.92.10 on
Adobe Flash Player 10.1.82.76 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.92.10 on Android; authplay.dll in Adobe Reader and Acrobat 9.x before 9.4; and authplay.dll in Adobe Reader and Acrobat 8.x before 8.2.5 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unsp
nvd
CVE-2017-16383P2HIGHCVSS 8.8Exploited≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16383 [HIGH] CWE-119 CVE-2017-16383: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a heap overflow vulnerability when processing a JPEG file embedded within an XPS document.
nvd
CVE-2023-26397P1MEDIUMCVSS 5.5Exploited≥ 20.001.3005, ≤ 20.005.30441≥ unspecified, ≤ 23.001.200932023-04-12
CVE-2023-26397 [MEDIUM] CWE-125 CVE-2023-26397: Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected
Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must ope
nvd
CVE-2017-16391P2HIGHCVSS 8.8Exploited≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16391 [HIGH] CWE-129 CVE-2017-16391: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is a result of untrusted input that is used to calculate an array index; the calculation occurs in the printing functionality. The vulner
nvd
CVE-2018-4893P2MEDIUMCVSS 6.5Exploited≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4893 [MEDIUM] CWE-125 CVE-2018-4893: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070
An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of XPS font processing. A successful attack can lead to sen
nvd
CVE-2011-4369P2CRITICALCVSS 10.0Exploitedv9.0v9.1+22 more2011-12-16
CVE-2011-4369 [CRITICAL] CVE-2011-4369: Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windo
Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6 on Mac OS X, Adobe Reader and Acrobat 10.x through 10.1.1 on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX allows remote attackers to execute arbitrary code or cause a denial of service (memory
nvd
CVE-2011-2107P2MEDIUMCVSS 4.3Exploited≤ 10.0.3v9.0+18 more2011-06-09
CVE-2011-2107 [MEDIUM] CWE-79 CVE-2011-2107: Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.181.22 on Windows, Mac OS
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.181.22 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.22 and earlier on Android, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "universal cross-site scripting vulnerability."
nvd
CVE-2008-2641P2CRITICALCVSS 10.0Exploitedv3.0v4.0+30 more2008-06-25
CVE-2008-2641 [CRITICAL] CVE-2008-2641: Unspecified vulnerability in Adobe Reader and Acrobat 7.0.9 and earlier, and 8.0 through 8.1.2, allo
Unspecified vulnerability in Adobe Reader and Acrobat 7.0.9 and earlier, and 8.0 through 8.1.2, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors, related to an "input validation issue in a JavaScript method."
nvd
CVE-2010-1241P2CRITICALCVSS 9.3Exploitedv8.0v8.1+16 more2010-04-05
CVE-2010-1241 [CRITICAL] CWE-119 CVE-2010-1241: Heap-based buffer overflow in the custom heap management system in Adobe Reader and Acrobat 9.x befo
Heap-based buffer overflow in the custom heap management system in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, aka FG-VD-10-005.
nvd
CVE-2007-5020P2CRITICALCVSS 9.3Exploitedv8.12007-09-21
CVE-2007-5020 [CRITICAL] CWE-94 CVE-2007-5020: Unspecified vulnerability in Adobe Acrobat and Reader 8.1 on Windows allows remote attackers to exec
Unspecified vulnerability in Adobe Acrobat and Reader 8.1 on Windows allows remote attackers to execute arbitrary code via a crafted PDF file, related to the mailto: option and Internet Explorer 7 on Windows XP. NOTE: this information is based upon a vague pre-advisory by a reliable researcher.
nvd