Adobe Acrobat Reader vulnerabilities
1,132 known vulnerabilities affecting adobe/acrobat_reader.
Total CVEs
1,132
CISA KEV
22
actively exploited
Public exploits
46
Exploited in wild
42
Severity breakdown
CRITICAL350HIGH432MEDIUM321LOW29
Vulnerabilities
Page 33 of 57
CVE-2011-0610P3CRITICALCVSS 9.3v9.0v9.1+17 more2011-05-03
CVE-2011-0610 [CRITICAL] CWE-119 CVE-2011-0610: The CoolType library in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Read
The CoolType library in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecifie
nvd
CVE-2015-6713P3HIGHCVSS 7.5≥ 10.0, ≤ 10.1.15≥ 11.0.0, ≤ 11.0.122015-10-14
CVE-2015-6713 [HIGH] CVE-2015-6713: The Function call implementation in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.
The Function call implementation in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnera
nvd
CVE-2025-64785P3HIGHCVSS 7.8≥ 20.001.3005, < 20.005.30838≤ 20.005.308032025-12-09
CVE-2025-64785 [HIGH] CWE-426 CVE-2025-64785: Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and ear
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a search path to locate critical resources such as programs, an attacker could m
nvd
CVE-2025-54257P3HIGHCVSS 7.8≥ 20.001.30002, < 20.005.30791≤ 25.001.206722025-09-09
CVE-2025-54257 [HIGH] CWE-416 CVE-2025-54257: Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use A
Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file, and scope is unchanged.
nvd
CVE-2026-27278P3HIGHCVSS 7.8≤ 25.001.212652026-03-10
CVE-2026-27278 [HIGH] CWE-416 CVE-2026-27278: Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use A
Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-47916P3HIGHCVSS 7.8≤ 26.001.216512026-06-09
CVE-2026-47916 [HIGH] CWE-416 CVE-2026-47916: Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vuln
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2020-9695P3HIGHCVSS 7.8v20.001.30002≤ 2015.006.305232026-06-23
CVE-2020-9695 [HIGH] CWE-787 CVE-2020-9695: Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier a
Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-47959P3HIGHCVSS 7.8fixed in 26.001.21662≤ 26.001.216512026-06-09
CVE-2026-47959 [HIGH] CWE-121 CVE-2026-47959: Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Stack-based Buffer
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-47921P3HIGHCVSS 7.8≤ 26.001.216512026-06-09
CVE-2026-47921 [HIGH] CWE-416 CVE-2026-47921: Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vuln
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-47920P3HIGHCVSS 7.8≤ 26.001.216512026-06-09
CVE-2026-47920 [HIGH] CWE-416 CVE-2026-47920: Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vuln
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-47955P3HIGHCVSS 7.8≤ 26.001.216512026-06-09
CVE-2026-47955 [HIGH] CWE-416 CVE-2026-47955: Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vuln
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2021-40726P3HIGHCVSS 7.8≥ unspecified, ≤ 2020.004.300062021-10-07
CVE-2021-40726 [HIGH] CWE-416 CVE-2021-40726: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability when processing AcroForm field that could result in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability in that the tar
nvd
CVE-2021-40725P3HIGHCVSS 7.8≥ unspecified, ≤ 2020.004.300062021-10-07
CVE-2021-40725 [HIGH] CWE-416 CVE-2021-40725: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability when processing AcroForm listbox that could result in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability in that the t
nvd
CVE-2015-7614P3MEDIUMCVSS 6.8≥ 10.0, ≤ 10.1.15≥ 11.0.0, ≤ 11.0.122015-10-14
CVE-2015-7614 [MEDIUM] CVE-2015-7614: Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions and execute arbitrary commands via an app.launchURL call, a different vulnerabil
nvd
CVE-2009-2993P3CRITICALCVSS 9.3≤ 9.1.3v7.0+24 more2009-10-19
CVE-2009-2993 [CRITICAL] CWE-20 CVE-2009-2993: The JavaScript for Acrobat API in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9
The JavaScript for Acrobat API in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 does not properly implement the (1) Privileged Context and (2) Safe Path restrictions for unspecified JavaScript methods, which allows remote attackers to create arbitrary files, and possibly execute arbitrary code, via the cPath paramete
nvd
CVE-2011-2106P3CRITICALCVSS 9.3v8.0v8.1+33 more2011-06-16
CVE-2011-2106 [CRITICAL] CWE-119 CVE-2011-2106: Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Mac OS X allow at
Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2011-2103P3CRITICALCVSS 9.3v8.0v8.1+13 more2011-06-16
CVE-2011-2103 [CRITICAL] CWE-119 CVE-2011-2103: Adobe Reader and Acrobat 8.x before 8.3 on Windows and Mac OS X allow attackers to execute arbitrary
Adobe Reader and Acrobat 8.x before 8.3 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2015-4452P3CRITICALCVSS 9.3≥ 10.0, ≤ 10.1.14≥ 11.0.0, ≤ 11.0.112015-07-15
CVE-2015-4452 [CRITICAL] CVE-2015-4452: Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-4435, CVE-201
nvd
CVE-2015-4451P3CRITICALCVSS 9.3≥ 10.0, ≤ 10.1.14≥ 11.0.0, ≤ 11.0.112015-07-15
CVE-2015-4451 [CRITICAL] CVE-2015-4451: Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-4435, CVE-201
nvd
CVE-2022-28239P3HIGHCVSS 7.8≥ 17.011.30059, ≤ 17.012.30205≥ 20.001.30005, ≤ 20.005.30314+2 more2022-05-11
CVE-2022-28239 [HIGH] CWE-125 CVE-2022-28239: Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (a
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the
nvd