Adobe Acrobat Reader vulnerabilities
1,132 known vulnerabilities affecting adobe/acrobat_reader.
Total CVEs
1,132
CISA KEV
22
actively exploited
Public exploits
46
Exploited in wild
42
Severity breakdown
CRITICAL350HIGH432MEDIUM321LOW29
Vulnerabilities
Page 46 of 57
CVE-2014-9150P4MEDIUMCVSS 6.4≤ 11.0.8v11.0+7 more2014-11-30
CVE-2014-9150 [MEDIUM] CVE-2014-9150: Race condition in the MoveFileEx call hook feature in Adobe Reader and Acrobat 11.x before 11.0.09 o
Race condition in the MoveFileEx call hook feature in Adobe Reader and Acrobat 11.x before 11.0.09 on Windows allows attackers to bypass a sandbox protection mechanism, and consequently write to files in arbitrary locations, via an NTFS junction attack, a similar issue to CVE-2014-0568.
nvd
CVE-2024-39425P4HIGHCVSS 7.0≥ 20.001.3005, < 20.005.30655≤ 24.001.301232024-08-14
CVE-2024-39425 [HIGH] CWE-367 CVE-2024-39425: Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affec
Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to privilege escalation. Exploitation of this issue require local low-privilege access to the affected system and attack complexity is high.
nvd
CVE-2021-28546P4MEDIUMCVSS 6.5≥ 17.011.30059, ≤ 17.011.30188≥ 20.001.30005, ≤ 20.001.30018+1 more2021-04-01
CVE-2021-28546 [MEDIUM] CWE-353 CVE-2021-28546: Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are missing support for an integrity check. An unauthenticated attacker could leverage this vulnerability to modify content in a certified PDF without invalidating the certification. Exploitation of this issue requires user
nvd
CVE-2026-34626P4MEDIUMCVSS 6.3≤ 26.001.214112026-04-14
CVE-2026-34626 [MEDIUM] CWE-1321 CVE-2026-34626: Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Impr
Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary file system read in the context of the current user. Exploitation of this issue requires user interaction in that a vic
nvd
CVE-2004-1153P4CRITICALCVSS 10.0v6.0v6.0.2+1 more2005-01-10
CVE-2004-1153 [CRITICAL] CVE-2004-1153: Format string vulnerability in Adobe Acrobat Reader 6.0.0 through 6.0.2 allows remote attackers to c
Format string vulnerability in Adobe Acrobat Reader 6.0.0 through 6.0.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an .ETD document containing format string specifiers in (1) title or (2) baseurl fields.
nvd
CVE-2021-45063P4MEDIUMCVSS 5.5≥ 17.011.30059, ≤ 17.011.30204≥ 20.001.30005, ≤ 20.004.30017+1 more2022-01-14
CVE-2021-45063 [MEDIUM] CWE-416 CVE-2021-45063: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of t
nvd
CVE-2021-44742P4MEDIUMCVSS 5.5≥ 17.011.30059, ≤ 17.011.30204≥ 20.001.30005, ≤ 20.004.30017+1 more2022-01-14
CVE-2021-44742 [MEDIUM] CWE-125 CVE-2021-44742: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of th
nvd
CVE-2022-28244P4MEDIUMCVSS 6.3≥ 17.011.30059, ≤ 17.012.30205≥ 20.001.30005, ≤ 20.005.30314+2 more2022-05-11
CVE-2022-28244 [MEDIUM] CWE-657 CVE-2022-28244: Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by a violation of secure design principles through bypassing the content security policy, which could result in an attacker sending arbitrarily configured requests to the cross-origin attack target domain. Exploitation require
nvd
CVE-2010-0186P4MEDIUMCVSS 6.8≤ 9.3v8.0+13 more2010-02-15
CVE-2010-0186 [MEDIUM] CVE-2010-0186: Cross-domain vulnerability in Adobe Flash Player before 10.0.45.2, Adobe AIR before 1.5.3.9130, and
Cross-domain vulnerability in Adobe Flash Player before 10.0.45.2, Adobe AIR before 1.5.3.9130, and Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows remote attackers to bypass intended sandbox restrictions and make cross-domain requests via unspecified vectors.
nvd
CVE-2007-0048P4MEDIUMCVSS 5.0≤ 7.0.8v6.0+14 more2007-01-03
CVE-2007-0048 [MEDIUM] CVE-2007-0048: Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x
Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, when used with Internet Explorer, Google Chrome, or Opera, allows remote attackers to cause a denial of service (memory consumption) via a long sequence of # (hash) characters appended to a PDF URL, related to
nvd
CVE-2007-0047P4MEDIUMCVSS 6.8≤ 7.0.82007-01-03
CVE-2007-0047 [MEDIUM] CVE-2007-0047: CRLF injection vulnerability in Adobe Acrobat Reader Plugin before 8.0.0, when used with the Microso
CRLF injection vulnerability in Adobe Acrobat Reader Plugin before 8.0.0, when used with the Microsoft.XMLHTTP ActiveX object in Internet Explorer, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the javascript: URI in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.
nvd
CVE-2015-5090P4HIGHCVSS 7.2≥ 10.0, ≤ 10.1.14≥ 11.0.0, ≤ 11.0.112015-07-15
CVE-2015-5090 [HIGH] CVE-2015-5090: Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and perform a transition from Low Integrity to Medium Integrity via unspecified vectors, a
nvd
CVE-2022-34233P4MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.005.30334≥ 20.001.30005, ≤ 20.005.30331+3 more2022-07-15
CVE-2022-34233 [MEDIUM] CWE-416 CVE-2022-34233: Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.3022
Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in
nvd
CVE-2015-3058P4MEDIUMCVSS 5.0v10.1.0v10.1.1+23 more2015-05-13
CVE-2015-3058 [MEDIUM] CWE-200 CVE-2015-3058: Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attac
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to obtain sensitive information from process memory via unspecified vectors.
nvd
CVE-2000-0713P4HIGHCVSS 7.6v3.0v4.0+1 more2000-10-20
CVE-2000-0713 [HIGH] CVE-2000-0713: Buffer overflow in Adobe Acrobat 4.05, Reader, Business Tools, and Fill In products that handle PDF
Buffer overflow in Adobe Acrobat 4.05, Reader, Business Tools, and Fill In products that handle PDF files allows attackers to execute arbitrary commands via a long /Registry or /Ordering specifier.
nvd
CVE-2022-35668P4MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.005.30362≥ 17.011.30059, ≤ 17.012.30249+1 more2022-08-11
CVE-2022-35668 [MEDIUM] CWE-20 CVE-2022-35668: Adobe Acrobat Reader versions 22.001.20169 (and earlier), 20.005.30362 (and earlier) and 17.012.3024
Adobe Acrobat Reader versions 22.001.20169 (and earlier), 20.005.30362 (and earlier) and 17.012.30249 (and earlier) are affected by an Improper Input Validation vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user int
nvd
CVE-2021-45067P4MEDIUMCVSS 5.5≥ 17.011.30059, ≤ 17.011.30204≥ 20.001.30005, ≤ 20.004.30017+1 more2022-01-14
CVE-2021-45067 [MEDIUM] CWE-788 CVE-2021-45067: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an Access of Memory Location After End of Buffer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue
nvd
CVE-2024-20734P4MEDIUMCVSS 5.5≥ 20.001.30005, < 20.005.30574≤ 23.008.204702024-02-15
CVE-2024-20734 [MEDIUM] CWE-416 CVE-2024-20734: Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vuln
Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2024-20736P4MEDIUMCVSS 5.5≥ 20.001.30005, < 20.005.30574≤ 23.008.204702024-02-15
CVE-2024-20736 [MEDIUM] CWE-125 CVE-2024-20736: Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read
Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2022-34232P4MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.005.30334≥ 20.001.30005, ≤ 20.005.30331+3 more2022-07-15
CVE-2022-34232 [MEDIUM] CWE-416 CVE-2022-34232: Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.3022
Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in
nvd