Adobe Acrobat Reader vulnerabilities

1,107 known vulnerabilities affecting adobe/acrobat_reader.

Total CVEs
1,107
CISA KEV
21
actively exploited
Public exploits
43
Exploited in wild
25
Severity breakdown
CRITICAL352HIGH412MEDIUM316LOW27

Vulnerabilities

Page 24 of 56
CVE-2018-4893MEDIUMCVSS 6.5≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4893 [MEDIUM] CWE-125 CVE-2018-4893: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of XPS font processing. A successful attack can lead to sen
nvd
CVE-2018-4907MEDIUMCVSS 6.5≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4907 [MEDIUM] CWE-125 CVE-2018-4907: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the TIFF processing in the XPS module. A successful atta
nvd
CVE-2018-4908MEDIUMCVSS 6.5≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4908 [MEDIUM] CWE-125 CVE-2018-4908: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the TTF font processing in the XPS module. A successful
nvd
CVE-2018-4881MEDIUMCVSS 6.5≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4881 [MEDIUM] CWE-125 CVE-2018-4881: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion module that reads bitmap image file
nvd
CVE-2018-4883MEDIUMCVSS 6.5≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4883 [MEDIUM] CWE-125 CVE-2018-4883: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs because of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion engine that handles Enhanced Metafile F
nvd
CVE-2018-4882MEDIUMCVSS 6.5≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4882 [MEDIUM] CWE-125 CVE-2018-4882: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the string literal parser. A successful attack can lead
nvd
CVE-2018-4906MEDIUMCVSS 6.5≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4906 [MEDIUM] CWE-125 CVE-2018-4906: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion module that handles Enhanced Metafi
nvd
CVE-2018-4884MEDIUMCVSS 6.5≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4884 [MEDIUM] CWE-125 CVE-2018-4884: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion engine when processing Enhanced Met
nvd
CVE-2018-4891MEDIUMCVSS 6.5≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4891 [MEDIUM] CWE-125 CVE-2018-4891: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the XPS module that handles TIFF data. A successful atta
nvd
CVE-2018-4880MEDIUMCVSS 6.5≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4880 [MEDIUM] CWE-125 CVE-2018-4880: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the conversion module that reads U3D data. A successful
nvd
CVE-2018-4897MEDIUMCVSS 6.5≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4897 [MEDIUM] CWE-125 CVE-2018-4897: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion module that parses TIFF metadata. A
nvd
CVE-2018-4887MEDIUMCVSS 6.5≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4887 [MEDIUM] CWE-125 CVE-2018-4887: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the Unicode mapping module that is invoked when processi
nvd
CVE-2018-4894MEDIUMCVSS 6.5≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4894 [MEDIUM] CWE-125 CVE-2018-4894: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the XPS font processing. A successful attack can lead to
nvd
CVE-2018-4912MEDIUMCVSS 6.5≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4912 [MEDIUM] CWE-125 CVE-2018-4912: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion module that handles JPEG 2000 data.
nvd
CVE-2018-4903MEDIUMCVSS 6.5≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4903 [MEDIUM] CWE-125 CVE-2018-4903: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the TIFF processing within the XPS module. A successful
nvd
CVE-2017-16398CRITICALCVSS 9.8≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16398 [CRITICAL] CWE-416 CVE-2017-16398: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the JavaScript engine. The mismatch between an old and a new object can provide
nvd
CVE-2017-11293CRITICALCVSS 9.8≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-11293 [CRITICAL] CWE-119 CVE-2017-11293: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-16410HIGHCVSS 8.8≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16410 [HIGH] CWE-129 CVE-2017-16410: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is a result of untrusted input that is used to calculate an array index; the calculation occurs in the image conversion module, when proc
nvd
CVE-2017-16400HIGHCVSS 8.8≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16400 [HIGH] CWE-125 CVE-2017-16400: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of the JPEG 2000
nvd
CVE-2017-16365HIGHCVSS 8.8≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16365 [HIGH] CWE-125 CVE-2017-16365: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer over-read in the True Type2 Font parsing module. A corrupted cmap table input leads to a computation where the poin
nvd