cbcvebase.

Adobe Acrobat Reader vulnerabilities

1,132 known vulnerabilities affecting adobe/acrobat_reader.

Total CVEs
1,132
CISA KEV
22
actively exploited
Public exploits
46
Exploited in wild
42
Severity breakdown
CRITICAL350HIGH432MEDIUM321LOW29

Vulnerabilities

Page 3 of 57
CVE-2009-3957P2MEDIUMCVSS 5.0Exploited≤ 9.2v3.0+48 more2010-01-13
CVE-2009-3957 [MEDIUM] CVE-2009-3957: Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow att Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow attackers to cause a denial of service (NULL pointer dereference) via unspecified vectors.
nvd
CVE-2008-2042P2CRITICALCVSS 9.3Exploited≤ 8.1.1v3.0+39 more2008-05-08
CVE-2008-2042 [CRITICAL] CWE-20 CVE-2008-2042: The Javascript API in Adobe Acrobat Professional 7.0.9 and possibly 8.1.1 exposes a dangerous method The Javascript API in Adobe Acrobat Professional 7.0.9 and possibly 8.1.1 exposes a dangerous method, which allows remote attackers to execute arbitrary commands or trigger a buffer overflow via a crafted PDF file that invokes app.checkForUpdate with a malicious callback function.
nvd
CVE-2013-2730P2CRITICALCVSS 10.0PoCv11.0v11.0.1+36 more2013-05-16
CVE-2013-2730 [CRITICAL] CWE-119 CVE-2013-2730: Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11 Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2733.
nvd
CVE-2009-3958P2CRITICALCVSS 10.0PoC≤ 9.2v3.0+48 more2010-01-13
CVE-2009-3958 [CRITICAL] CWE-119 CVE-2009-3958: Multiple stack-based buffer overflows in the NOS Microsystems getPlus Helper ActiveX control before Multiple stack-based buffer overflows in the NOS Microsystems getPlus Helper ActiveX control before 1.6.2.49 in gp.ocx in the Download Manager in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow remote attackers to execute arbitrary code via unspecified initialization parameters.
nvd
CVE-2015-7622P2CRITICALCVSS 10.0PoC≥ 10.0, ≤ 10.1.15≥ 11.0.0, ≤ 11.0.122015-10-14
CVE-2015-7622 [CRITICAL] CVE-2015-7622: Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability
nvd
CVE-2015-3073P2CRITICALCVSS 10.0PoCv10.1.0v10.1.1+23 more2015-05-13
CVE-2015-3073 [CRITICAL] CVE-2015-3073: Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attac Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE
nvd
CVE-2007-0046P3HIGHCVSS 7.5PoC≤ 7.0.82007-01-03
CVE-2007-0046 [HIGH] CVE-2007-0046: Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefo Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute arbitrary code by causing an error via a javascript: URI call to document.write in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.
nvd
CVE-2010-2201P2CRITICALCVSS 9.3PoCv9.0v9.1+17 more2010-06-30
CVE-2010-2201 [CRITICAL] CVE-2010-2201: Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attac Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with crafted Flash content involving the (1) pushstring (0x2C) operator, (2) debugfile (0xF1) operator, and an "invalid pointer vulnerability" that triggers memory corruption, a different vulnerability than CVE-20
nvd
CVE-2010-2168P2CRITICALCVSS 9.3PoCv9.0v9.1+17 more2010-06-30
CVE-2010-2168 [CRITICAL] CVE-2010-2168: Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attac Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with crafted Flash content, involving the newfunction (0x44) operator and an "invalid pointer vulnerability" that triggers memory corruption, a different vulnerability than CVE-2010-1285 and CVE-2010-2201.
nvd
CVE-2009-2994P3CRITICALCVSS 9.3PoC≤ 9.1.3v7.0+24 more2009-10-19
CVE-2009-2994 [CRITICAL] CWE-119 CVE-2009-2994: Buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 m Buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2010-4091P3CRITICALCVSS 9.3PoCv8.0v8.1+24 more2010-11-07
CVE-2010-4091 [CRITICAL] CWE-119 CVE-2010-4091: The EScript.api plugin in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.1, and 8.x bef The EScript.api plugin in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.1, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document that triggers memory corruption, involving the printSeps function. NOTE: some of these deta
nvd
CVE-2010-3631P3CRITICALCVSS 9.3PoCv8.0v8.1+22 more2010-10-06
CVE-2010-3631 [CRITICAL] CWE-20 CVE-2010-3631: Array index error in Adobe Reader and Acrobat 8.x before 8.2.5 and 9.x before 9.4 on Mac OS X allows Array index error in Adobe Reader and Acrobat 8.x before 8.2.5 and 9.x before 9.4 on Mac OS X allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2021-28560P2HIGHCVSS 8.8≥ 17.011.30059, ≤ 17.011.30194≥ 20.001.30005, ≤ 20.001.30020+1 more2021-09-02
CVE-2021-28560 [HIGH] CWE-122 CVE-2021-28560: Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2 Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requ
nvd
CVE-2010-2204P3CRITICALCVSS 9.3PoCv9.0v9.1+17 more2010-06-30
CVE-2010-2204 [CRITICAL] CVE-2010-2204: Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Wind Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2021-39843P2HIGHCVSS 7.8≥ 20.001.30005, ≤ 20.004.30006≥ 17.011.30059, ≤ 17.011.30199+1 more2021-09-29
CVE-2021-39843 [HIGH] CWE-787 CVE-2021-39843: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2009-2983P3CRITICALCVSS 9.3PoC≤ 9.1.3v7.0+24 more2009-10-19
CVE-2009-2983 [CRITICAL] CWE-399 CVE-2009-2983: Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 allow atta Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.
nvd
CVE-2021-39836P2HIGHCVSS 7.8≥ 17.011.30059, ≤ 17.011.30199≥ 20.001.30005, ≤ 20.004.30006+1 more2021-09-29
CVE-2021-39836 [HIGH] CWE-416 CVE-2021-39836: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm buttonGetIcon action that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti
nvd
CVE-2008-2549P3MEDIUMCVSS 4.3PoC≤ 8.1.2v3.0+30 more2008-06-04
CVE-2008-2549 [MEDIUM] CVE-2008-2549: Adobe Acrobat Reader 8.1.2 and earlier, and before 7.1.1, allows remote attackers to cause a denial Adobe Acrobat Reader 8.1.2 and earlier, and before 7.1.1, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed PDF document, as demonstrated by 2008-HI2.pdf.
nvd
CVE-2021-28639P2HIGHCVSS 7.8≥ unspecified, ≤ 2020.004.300052021-08-20
CVE-2021-28639 [HIGH] CWE-416 CVE-2021-28639: Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Use-after-free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interactio
nvd
CVE-2021-39838P3HIGHCVSS 7.8≥ 20.001.30005, ≤ 20.004.30006≥ 17.011.30059, ≤ 17.011.30199+1 more2021-09-29
CVE-2021-39838 [HIGH] CWE-416 CVE-2021-39838: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm buttonGetCaption action that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user intera
nvd
Adobe Acrobat Reader vulnerabilities | cvebase