cbcvebase.

Adobe Acrobat Reader vulnerabilities

1,132 known vulnerabilities affecting adobe/acrobat_reader.

Total CVEs
1,132
CISA KEV
22
actively exploited
Public exploits
46
Exploited in wild
42
Severity breakdown
CRITICAL350HIGH432MEDIUM321LOW29

Vulnerabilities

Page 35 of 57
CVE-2010-2207P3CRITICALCVSS 9.3v9.0v9.1+17 more2010-06-30
CVE-2010-2207 [CRITICAL] CVE-2010-2207: Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attac Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2209, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.
nvd
CVE-2010-2209P3CRITICALCVSS 9.3v9.0v9.1+17 more2010-06-30
CVE-2010-2209 [CRITICAL] CVE-2010-2209: Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attac Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.
nvd
CVE-2009-4764P3CRITICALCVSS 9.3v8.0v8.1+13 more2010-04-05
CVE-2009-4764 [CRITICAL] CWE-94 CVE-2009-4764: Adobe Reader 8.x and 9.x on Windows is able to execute EXE files that are embedded in a PDF document Adobe Reader 8.x and 9.x on Windows is able to execute EXE files that are embedded in a PDF document, which makes it easier for remote attackers to trick users into executing arbitrary code via a crafted document.
nvd
CVE-2024-41879P3HIGHCVSS 7.8≤ 127.0.2651.1052024-08-26
CVE-2024-41879 [HIGH] CWE-787 CVE-2024-41879: Acrobat Reader versions 127.0.2651.105 and earlier are affected by an out-of-bounds write vulnerabil Acrobat Reader versions 127.0.2651.105 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-43576P3HIGHCVSS 7.8≥ 20.001.30002, < 20.005.30774≤ 25.001.205212025-06-10
CVE-2025-43576 [HIGH] CWE-416 CVE-2025-43576: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use A Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-43577P3HIGHCVSS 7.8≥ 20.001.30002, < 20.005.30774≤ 25.001.205212025-06-10
CVE-2025-43577 [HIGH] CWE-416 CVE-2025-43577: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use A Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-43550P3HIGHCVSS 7.8≥ 20.001.30002, < 20.005.30774≤ 25.001.205212025-06-10
CVE-2025-43550 [HIGH] CWE-416 CVE-2025-43550: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use A Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-43574P3HIGHCVSS 7.8≥ 20.001.30002, < 20.005.30774≤ 25.001.205212025-06-10
CVE-2025-43574 [HIGH] CWE-416 CVE-2025-43574: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use A Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2025-43573P3HIGHCVSS 7.8≥ 20.001.30002, < 20.005.30774≤ 25.001.205212025-06-10
CVE-2025-43573 [HIGH] CWE-416 CVE-2025-43573: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use A Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2022-44518P3HIGHCVSS 7.8≥ 17.011.30059, ≤ 17.012.30205≥ 20.001.30005, ≤ 20.005.30314+2 more2024-12-19
CVE-2022-44518 [HIGH] CWE-416 CVE-2022-44518: Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (a Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2022-44514P3HIGHCVSS 7.8≥ 17.011.30059, ≤ 17.012.30205≥ 20.001.30005, ≤ 20.005.30314+2 more2024-12-19
CVE-2022-44514 [HIGH] CWE-416 CVE-2022-44514: Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (a Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2022-44520P3HIGHCVSS 7.8≥ 17.011.30059, ≤ 17.012.30205≥ 20.001.30005, ≤ 20.005.30314+2 more2024-12-19
CVE-2022-44520 [HIGH] CWE-416 CVE-2022-44520: Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (a Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2022-44513P3HIGHCVSS 7.8≥ 17.011.30059, ≤ 17.012.30205≥ 20.001.30005, ≤ 20.005.30314+2 more2024-12-19
CVE-2022-44513 [HIGH] CWE-787 CVE-2022-44513: Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (a Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2022-44512P3HIGHCVSS 7.8≥ 17.011.30059, ≤ 17.012.30205≥ 20.001.30005, ≤ 20.005.30314+2 more2024-12-19
CVE-2022-44512 [HIGH] CWE-787 CVE-2022-44512: Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (a Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2026-47952P3HIGHCVSS 7.8≤ 26.001.216512026-06-09
CVE-2026-47952 [HIGH] CWE-122 CVE-2026-47952: Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Heap-based Buffer O Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-34129P3HIGHCVSS 7.5fixed in 24.5.0.336942024-06-13
CVE-2024-34129 [HIGH] CWE-22 CVE-2024-34129: Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Improper Limitation Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability to access files and directories that are outside the restricted directory and also to o
nvd
CVE-2021-21042P3MEDIUMCVSS 6.5≥ 17.0, ≤ 17.011.30188≥ 20.0, ≤ 20.001.300183+1 more2021-02-11
CVE-2021-21042 [MEDIUM] CWE-125 CVE-2021-21042: Acrobat Reader DC versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an Out-of-bounds Read vulnerability that could lead to arbitrary disclosure of information in the memory stack. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this i
nvd
CVE-2006-6236P3CRITICALCVSS 9.3v7.0v7.0.1+7 more2006-12-03
CVE-2006-6236 [CRITICAL] CVE-2006-6236: Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of s Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the (1) src, (2) setPageMode, (3) setLayoutMode, and (4) setNamedDest methods in an AcroPDF ActiveX control, a different set of vectors than CVE-2006-6027.
nvd
CVE-2017-16366P3HIGHCVSS 7.5≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16366 [HIGH] CVE-2017-16366: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a security bypass vulnerability in the AcroPDF plugin.
nvd
CVE-2015-5109P3MEDIUMCVSS 6.8≥ 10.0, < 10.1.15≥ 11.0.0, < 11.0.122015-07-15
CVE-2015-5109 [MEDIUM] CVE-2015-5109: Integer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat an Integer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5097 and CVE-20
nvd
Adobe Acrobat Reader vulnerabilities | cvebase