Adobe Acrobat Reader vulnerabilities
1,132 known vulnerabilities affecting adobe/acrobat_reader.
Total CVEs
1,132
CISA KEV
22
actively exploited
Public exploits
46
Exploited in wild
42
Severity breakdown
CRITICAL350HIGH432MEDIUM321LOW29
Vulnerabilities
Page 20 of 57
CVE-2016-1111P3HIGHCVSS 8.8≤ 9.02016-04-30
CVE-2016-1111 [HIGH] CVE-2016-1111: Double free vulnerability in Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC
Double free vulnerability in Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allows attackers to execute arbitrary code via a crafted Graphics State dictionary.
nvd
CVE-2009-0193P3CRITICALCVSS 9.3≥ 7.0, < 7.1.1≥ 8.0, < 8.1.4+1 more2009-03-25
CVE-2009-0193 [CRITICAL] CWE-119 CVE-2009-0193: Heap-based buffer overflow in Adobe Acrobat Reader 9 before 9.1, 8 before 8.1.4, and 7 before 7.1.1
Heap-based buffer overflow in Adobe Acrobat Reader 9 before 9.1, 8 before 8.1.4, and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a PDF file with a malformed JBIG2 symbol dictionary segment, a different vulnerability than CVE-2009-1061 and CVE-2009-1062.
nvd
CVE-2011-2095P3CRITICALCVSS 9.3v8.0v8.1+33 more2011-06-16
CVE-2011-2095 [CRITICAL] CVE-2011-2095: Buffer overflow in Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 o
Buffer overflow in Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2094 and CVE-2011-2097.
nvd
CVE-2011-2094P3CRITICALCVSS 9.3v8.0v8.1+33 more2011-06-16
CVE-2011-2094 [CRITICAL] CWE-119 CVE-2011-2094: Buffer overflow in Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 o
Buffer overflow in Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2095 and CVE-2011-2097.
nvd
CVE-2009-2997P3CRITICALCVSS 9.3≤ 9.1.3v7.0+24 more2009-10-19
CVE-2009-2997 [CRITICAL] CWE-119 CVE-2009-2997: Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x b
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2013-2733P3CRITICALCVSS 10.0v9.0v9.1+36 more2013-05-16
CVE-2013-2733 [CRITICAL] CVE-2013-2733: Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2730.
nvd
CVE-2014-0566P3CRITICALCVSS 10.0≥ 10.0, < 10.1.15≥ 11.0.0, < 11.0.122014-09-17
CVE-2014-0566 [CRITICAL] CVE-2014-0566: Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allow attac
Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0565.
nvd
CVE-2013-2549P3HIGHCVSS 7.5v11.0.022013-03-11
CVE-2013-2549 [HIGH] CWE-94 CVE-2013-2549: Unspecified vulnerability in Adobe Reader 11.0.02 allows remote attackers to execute arbitrary code
Unspecified vulnerability in Adobe Reader 11.0.02 allows remote attackers to execute arbitrary code via vectors related to a "break into the sandbox," as demonstrated by George Hotz during a Pwn2Own competition at CanSecWest 2013.
nvd
CVE-2017-11307P3CRITICALCVSS 9.8≥ 11.0.0, ≤ 11.0.22≥ 17.011.30066, < 17.011.300682018-05-19
CVE-2017-11307 [CRITICAL] CWE-125 CVE-2017-11307: Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.3
Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
nvd
CVE-2017-11306P3CRITICALCVSS 9.8≥ 11.0.0, ≤ 11.0.22≥ 17.011.30066, < 17.011.300682018-05-19
CVE-2017-11306 [CRITICAL] CWE-125 CVE-2017-11306: Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.3
Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
nvd
CVE-2017-11240P3CRITICALCVSS 9.8≥ 11.0.0, ≤ 11.0.222018-05-19
CVE-2017-11240 [CRITICAL] CWE-125 CVE-2017-11240: Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.3
Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
nvd
CVE-2017-11250P3CRITICALCVSS 9.8≥ 11.0.0, ≤ 11.0.222018-05-19
CVE-2017-11250 [CRITICAL] CWE-125 CVE-2017-11250: Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.3
Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
nvd
CVE-2017-11253P3CRITICALCVSS 9.8≥ 11.0.0, ≤ 11.0.222018-05-19
CVE-2017-11253 [CRITICAL] CWE-125 CVE-2017-11253: Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.3
Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
nvd
CVE-2016-0933P3CRITICALCVSS 9.8≤ 11.0.13v11.0.0+12 more2016-01-14
CVE-2016-0933 [CRITICAL] CVE-2016-0933: Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119,
Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0931, CVE-2016-0936
nvd
CVE-2011-0602P3CRITICALCVSS 9.3v8.0v8.1+25 more2011-02-10
CVE-2011-0602 [CRITICAL] CVE-2011-0602: Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and M
Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via crafted JP2K record types in a JPEG2000 image in a PDF file, which causes heap corruption, a different vulnerability than CVE-2011-0596, CVE-2011-0598, and CVE-2011-0599.
nvd
CVE-2022-28243P3HIGHCVSS 7.8≥ 17.011.30059, ≤ 17.012.30205≥ 20.001.30005, ≤ 20.005.30314+2 more2022-05-11
CVE-2022-28243 [HIGH] CWE-125 CVE-2022-28243: Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (a
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the
nvd
CVE-2014-0526P3CRITICALCVSS 10.0v10.0v10.0.1+19 more2014-05-14
CVE-2014-0526 [CRITICAL] CVE-2014-0526: Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X allow attac
Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0522, CVE-2014-0523, and CVE-2014-0524.
nvd
CVE-2010-3620P3CRITICALCVSS 9.3v8.0v8.1+22 more2010-10-06
CVE-2010-3620 [CRITICAL] CWE-20 CVE-2010-3620: Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Window
Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execute arbitrary code via a crafted image, a different vulnerability than CVE-2010-3629.
nvd
CVE-2010-3629P3CRITICALCVSS 9.3v8.0v8.1+22 more2010-10-06
CVE-2010-3629 [CRITICAL] CVE-2010-3629: Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Window
Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execute arbitrary code via a crafted image, a different vulnerability than CVE-2010-3620.
nvd
CVE-2011-0590P3CRITICALCVSS 9.3v8.0v8.1+25 more2011-02-10
CVE-2011-0590 [CRITICAL] CWE-20 CVE-2011-0590: Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and M
Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via a 3D file, a different vulnerability than CVE-2011-0591, CVE-2011-0592, CVE-2011-0593, CVE-2011-0595, and CVE-2011-0600.
nvd