Adobe Acrobat Reader vulnerabilities
1,132 known vulnerabilities affecting adobe/acrobat_reader.
Total CVEs
1,132
CISA KEV
22
actively exploited
Public exploits
46
Exploited in wild
42
Severity breakdown
CRITICAL350HIGH432MEDIUM321LOW29
Vulnerabilities
Page 42 of 57
CVE-2018-4999P3MEDIUMCVSS 6.5≥ 17.011.30059, ≤ 17.011.300702018-07-09
CVE-2018-4999 [MEDIUM] CWE-125 CVE-2018-4999: Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, and 2015.0
Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, and 2015.006.30394 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
nvd
CVE-2023-21612P3HIGHCVSS 7.8≥ 20.001.30005, ≤ 20.005.30418≥ unspecified, ≤ 20.005.304182023-01-18
CVE-2023-21612 [HIGH] CWE-379 CVE-2023-21612: Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.3041
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in privilege escalation in the context of the current user. Exploitation of this issue requires user interaction in that
nvd
CVE-2023-21611P3HIGHCVSS 7.8≥ 20.001.30005, ≤ 20.005.30418≥ unspecified, ≤ 20.005.304182023-01-18
CVE-2023-21611 [HIGH] CWE-379 CVE-2023-21611: Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.3041
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in privilege escalation in the context of the current user. Exploitation of this issue requires user interaction in that
nvd
CVE-2025-27161P3HIGHCVSS 7.8≥ 20.001.30002, < 20.005.30763≤ 25.001.204282025-03-11
CVE-2025-27161 [HIGH] CWE-125 CVE-2025-27161: Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-
Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this
nvd
CVE-2015-5091P3HIGHCVSS 7.8≥ 10.0, < 10.1.15≥ 11.0.0, < 11.0.122015-07-15
CVE-2015-5091 [HIGH] CWE-20 CVE-2015-5091: Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to cause a denial of service via invalid data.
nvd
CVE-2017-11232P3MEDIUMCVSS 6.5≥ 17.011.00000, ≤ 17.011.300662017-08-11
CVE-2017-11232 [MEDIUM] CWE-200 CVE-2017-11232: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability when processing Enhanced Metafile Format (EMF) data related to brush manipulation. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2009-2028P3CRITICALCVSS 10.0v7.0v7.0.1+20 more2009-06-11
CVE-2009-2028 [CRITICAL] CVE-2009-2028: Multiple unspecified vulnerabilities in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 an
Multiple unspecified vulnerabilities in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 have unknown impact and attack vectors, related to "Adobe internally discovered issues."
nvd
CVE-2010-0196P3CRITICALCVSS 9.3v9.0v9.1+15 more2010-04-14
CVE-2010-0196 [CRITICAL] CVE-2010-0196: Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Wind
Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2010-0192 and CVE-2010-0193.
nvd
CVE-2009-2996P3CRITICALCVSS 9.3≤ 9.1.3v7.0+24 more2009-10-19
CVE-2009-2996 [CRITICAL] CVE-2009-2996: Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allow attackers to c
Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-2985.
nvd
CVE-2009-2985P3CRITICALCVSS 9.3≤ 9.1.3v7.0+24 more2009-10-19
CVE-2009-2985 [CRITICAL] CWE-399 CVE-2009-2985: Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allow attackers to c
Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-2996.
nvd
CVE-2020-24428P3HIGHCVSS 7.7≤ 20.001.30005≥ unspecified, ≤ 2017.011.301752020-11-05
CVE-2020-24428 [HIGH] CWE-367 CVE-2020-24428: Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) for macOS are affected by a time-of-check time-of-use (TOCTOU) race condition vulnerability that could result in local privilege escalation. Exploitation of this issue requires user interaction in that a victim must open a malicious f
nvd
CVE-2004-1152P3CRITICALCVSS 10.0v5.0.92005-01-10
CVE-2004-1152 [CRITICAL] CVE-2004-1152: Buffer overflow in the mailListIsPdf function in Adobe Acrobat Reader 5.09 for Unix allows remote at
Buffer overflow in the mailListIsPdf function in Adobe Acrobat Reader 5.09 for Unix allows remote attackers to execute arbitrary code via an e-mail message with a crafted PDF attachment.
nvd
CVE-2011-0564P3CRITICALCVSS 9.3v8.0v8.1+25 more2011-02-10
CVE-2011-0564 [CRITICAL] CWE-264 CVE-2011-0564: Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows use w
Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows use weak permissions for unspecified files, which allows attackers to gain privileges via unknown vectors.
nvd
CVE-2022-35672P3HIGHCVSS 7.8≥ 20.001.30005, ≤ 20.005.30314≥ 20.001.30005, ≤ 20.005.30311+2 more2022-07-27
CVE-2022-35672 [HIGH] CWE-125 CVE-2022-35672: Adobe Acrobat Reader version 22.001.20085 (and earlier), 20.005.30314 (and earlier) and 17.012.30205
Adobe Acrobat Reader version 22.001.20085 (and earlier), 20.005.30314 (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of t
nvd
CVE-2026-47937P3HIGHCVSS 7.7≤ 26.001.216512026-06-09
CVE-2026-47937 [HIGH] CWE-427 CVE-2026-47937: Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Searc
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interact
nvd
CVE-2012-0777P3MEDIUMCVSS 6.8≥ 9.0, < 9.5.1≥ 10.0, < 10.1.32012-04-10
CVE-2012-0777 [MEDIUM] CWE-119 CVE-2012-0777: The JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 on Mac OS X a
The JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 on Mac OS X and Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2020-29075P3MEDIUMCVSS 6.5≥ 17.011.30059, ≤ 17.011.30180≥ 20.001.30005, ≤ 20.001.300102021-02-23
CVE-2020-29075 [MEDIUM] CWE-20 CVE-2020-29075: Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) are affected by an information exposure vulnerability, that could enable an attacker to get a DNS interaction and track if the user has opened or closed a PDF file when loaded from the filesystem without a prompt. User interaction is
nvd
CVE-2015-7619P3MEDIUMCVSS 6.8≥ 10.0, ≤ 10.1.15≥ 11.0.0, ≤ 11.0.122015-10-14
CVE-2015-7619 [MEDIUM] CVE-2015-7619: The ANShareFile2 method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acr
The ANShareFile2 method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability
nvd
CVE-2015-6722P3MEDIUMCVSS 6.8≥ 10.0, ≤ 10.1.15≥ 11.0.0, ≤ 11.0.122015-10-14
CVE-2015-6722 [MEDIUM] CVE-2015-6722: The CBSharedReviewStatusDialog method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x befor
The CBSharedReviewStatusDialog method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different
nvd
CVE-2015-6714P3MEDIUMCVSS 6.8≥ 10.0, ≤ 10.1.15≥ 11.0.0, ≤ 11.0.122015-10-14
CVE-2015-6714 [MEDIUM] CVE-2015-6714: The Function bind implementation in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.
The Function bind implementation in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulne
nvd