Adobe Acrobat Reader vulnerabilities
1,132 known vulnerabilities affecting adobe/acrobat_reader.
Total CVEs
1,132
CISA KEV
22
actively exploited
Public exploits
46
Exploited in wild
42
Severity breakdown
CRITICAL350HIGH432MEDIUM321LOW29
Vulnerabilities
Page 39 of 57
CVE-2023-38246P3HIGHCVSS 7.8≥ 20.001.30005, < 20.005.30516.10516≥ 20.001.30005, < 20.005.30514.10514+1 more2023-08-10
CVE-2023-38246 [HIGH] CWE-824 CVE-2023-38246: Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2019-16471P3HIGHCVSS 7.8≤ 2019.021.200562023-09-11
CVE-2019-16471 [HIGH] CWE-416 CVE-2019-16471: Adobe Acrobat Reader versions 2019.021.20056 and earlier are affected by a Use After Free vulnerabil
Adobe Acrobat Reader versions 2019.021.20056 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2017-11236P3MEDIUMCVSS 6.5≥ 17.011.00000, ≤ 17.011.300662017-08-11
CVE-2017-11236 [MEDIUM] CWE-119 CVE-2017-11236: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the internal handling of UTF-16 literal strings. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2014-8452P3MEDIUMCVSS 5.0v10.0v10.0.1+25 more2014-12-10
CVE-2014-8452 [MEDIUM] CWE-200 CVE-2014-8452: Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow remot
Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2014-0512P3CRITICALCVSS 10.0v11.0.62014-03-27
CVE-2014-0512 [CRITICAL] CWE-264 CVE-2014-0512: Adobe Reader 11.0.06 allows attackers to bypass a PDF sandbox protection mechanism via unspecified v
Adobe Reader 11.0.06 allows attackers to bypass a PDF sandbox protection mechanism via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.
nvd
CVE-2017-11248P3MEDIUMCVSS 6.5≥ 17.011.00000, ≤ 17.011.300662017-08-11
CVE-2017-11248 [MEDIUM] CWE-119 CVE-2017-11248: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to pixel block transfer. Successful exploitation could lead to arbitrary code ex
nvd
CVE-2017-11233P3MEDIUMCVSS 6.5≥ 17.011.00000, ≤ 17.011.300662017-08-11
CVE-2017-11233 [MEDIUM] CWE-119 CVE-2017-11233: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to block transfer of pixels. Successful exploitation could lead to arbitrary cod
nvd
CVE-2017-11255P3MEDIUMCVSS 6.5≥ 17.011.00000, ≤ 17.011.300662017-08-11
CVE-2017-11255 [MEDIUM] CWE-119 CVE-2017-11255: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing TIFF color map data. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11258P3MEDIUMCVSS 6.5≥ 17.011.00000, ≤ 17.011.300662017-08-11
CVE-2017-11258 [MEDIUM] CWE-119 CVE-2017-11258: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data and the embedded GIF image. Successful exploitation could lead to arbitrary code
nvd
CVE-2017-11239P3MEDIUMCVSS 6.5≥ 17.011.00000, ≤ 17.011.300662017-08-11
CVE-2017-11239 [MEDIUM] CWE-119 CVE-2017-11239: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to text strings. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11238P3MEDIUMCVSS 6.5≥ 17.011.00000, ≤ 17.011.300662017-08-11
CVE-2017-11238 [MEDIUM] CWE-119 CVE-2017-11238: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to curve drawing. Successful exploitation could lead to arbitrary code execution
nvd
CVE-2015-4446P3HIGHCVSS 7.5≥ 10.0, < 10.1.15≥ 11.0.0, < 11.0.122015-07-15
CVE-2015-4446 [HIGH] CWE-269 CVE-2015-4446: Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and perform a transition from Low Integrity to Medium Integrity via unspecified vec
nvd
CVE-2015-7621P3MEDIUMCVSS 6.8≥ 10.0, ≤ 10.1.15≥ 11.0.0, ≤ 11.0.122015-10-14
CVE-2015-7621 [MEDIUM] CVE-2015-7621: Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13
Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to execute arbitrary code via a crafted U3D object, a different vulnerability than CVE-2015-55
nvd
CVE-2015-7617P3MEDIUMCVSS 6.8≥ 10.0, ≤ 10.1.15≥ 11.0.0, ≤ 11.0.122015-10-14
CVE-2015-7617 [MEDIUM] CVE-2015-7617: Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13
Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to execute arbitrary code by leveraging improper EScript exception handling, a different vulne
nvd
CVE-2011-0585P3CRITICALCVSS 9.3v8.0v8.1+25 more2011-02-10
CVE-2011-0585 [CRITICAL] CVE-2011-0585: Unspecified vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x
Unspecified vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0565.
nvd
CVE-2015-6689P3MEDIUMCVSS 6.8≥ 10.0, ≤ 10.1.15≥ 11.0.0, ≤ 11.0.122015-10-14
CVE-2015-6689 [MEDIUM] CVE-2015-6689: Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13
Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to execute arbitrary code via a crafted WillSave document action, a different vulnerability th
nvd
CVE-2004-0631P3CRITICALCVSS 10.0v5.0v5.0.5+1 more2004-08-18
CVE-2004-0631 [CRITICAL] CVE-2004-0631: Buffer overflow in the uudecoding feature for Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linu
Buffer overflow in the uudecoding feature for Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arbitrary code via a long filename for the PDF file that is provided to the uudecode command.
nvd
CVE-2020-24429P3HIGHCVSS 7.8≤ 20.001.30005≥ unspecified, ≤ 2017.011.301752020-11-05
CVE-2020-24429 [HIGH] CWE-347 CVE-2020-24429: Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) for macOS are affected by a signature verification bypass that could result in local privilege escalation. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2011-2102P3CRITICALCVSS 9.3v10.0v10.0.1+2 more2011-06-16
CVE-2011-2102 [CRITICAL] CVE-2011-2102: Unspecified vulnerability in Adobe Reader and Acrobat before 10.1 on Windows and Mac OS X allows att
Unspecified vulnerability in Adobe Reader and Acrobat before 10.1 on Windows and Mac OS X allows attackers to bypass intended access restrictions via unknown vectors.
nvd
CVE-2015-6694P3MEDIUMCVSS 6.8≥ 10.0, ≤ 10.1.15≥ 11.0.0, ≤ 11.0.122015-10-14
CVE-2015-6694 [MEDIUM] CVE-2015-6694: Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted use of the fillColor attribute, a differe
nvd