Adobe Acrobat Reader vulnerabilities
1,132 known vulnerabilities affecting adobe/acrobat_reader.
Total CVEs
1,132
CISA KEV
22
actively exploited
Public exploits
46
Exploited in wild
42
Severity breakdown
CRITICAL350HIGH432MEDIUM321LOW29
Vulnerabilities
Page 47 of 57
CVE-2022-34234P4MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.005.30334≥ 20.001.30005, ≤ 20.005.30331+3 more2022-07-15
CVE-2022-34234 [MEDIUM] CWE-416 CVE-2022-34234: Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.3022
Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in
nvd
CVE-2022-34237P4MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.005.30334≥ 20.001.30005, ≤ 20.005.30331+3 more2022-07-15
CVE-2022-34237 [MEDIUM] CWE-416 CVE-2022-34237: Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.3022
Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in
nvd
CVE-2022-34236P4MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.005.30334≥ 20.001.30005, ≤ 20.005.30331+3 more2022-07-15
CVE-2022-34236 [MEDIUM] CWE-125 CVE-2022-34236: Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.3022
Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interacti
nvd
CVE-2023-29303P4MEDIUMCVSS 5.5≥ 20.001.30005, < 20.005.30516.10516≥ 20.001.30005, < 20.005.30514.10514+1 more2023-08-10
CVE-2023-29303 [MEDIUM] CWE-416 CVE-2023-29303: Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a m
nvd
CVE-2022-34239P4MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.005.30334≥ 20.001.30005, ≤ 20.005.30331+3 more2022-07-15
CVE-2022-34239 [MEDIUM] CWE-125 CVE-2022-34239: Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.3022
Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interacti
nvd
CVE-2023-38230P4MEDIUMCVSS 5.5≥ 20.001.30005, < 20.005.30516.10516≥ 20.001.30005, < 20.005.30514.10514+1 more2023-08-10
CVE-2023-38230 [MEDIUM] CWE-416 CVE-2023-38230: Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use-After-Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a m
nvd
CVE-2021-39861P4MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.004.30006≥ unspecified, ≤ 2020.004.300062021-09-29
CVE-2021-39861 [MEDIUM] CWE-125 CVE-2021-39861: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a
nvd
CVE-2023-38232P4MEDIUMCVSS 5.5≥ 20.001.30005, < 20.005.30516.10516≥ 20.001.30005, < 20.005.30514.10514+1 more2023-08-10
CVE-2023-38232 [MEDIUM] CWE-125 CVE-2023-38232: Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must ope
nvd
CVE-2023-21585P4MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.005.30418≥ unspecified, ≤ 20.005.304182023-01-18
CVE-2023-21585 [MEDIUM] CWE-125 CVE-2023-21585: Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.3041
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interacti
nvd
CVE-2023-21614P4MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.005.30418≥ unspecified, ≤ 20.005.304182023-01-18
CVE-2023-21614 [MEDIUM] CWE-125 CVE-2023-21614: Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.3041
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interacti
nvd
CVE-2023-21613P4MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.005.30418≥ unspecified, ≤ 20.005.304182023-01-18
CVE-2023-21613 [MEDIUM] CWE-125 CVE-2023-21613: Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.3041
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interacti
nvd
CVE-2024-49535P4MEDIUMCVSS 6.3≥ 20.001.30002, < 20.005.30748≤ 20.005.307102024-12-10
CVE-2024-49535 [MEDIUM] CWE-611 CVE-2024-49535: Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and ear
Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that allows an attacker to provide malicious XML input containing a reference to an external entity, potentially leading to unauthorized read access ou
nvd
CVE-2023-21581P4MEDIUMCVSS 5.5≥ 20.001.30005, ≤ 20.005.30418≥ unspecified, ≤ 20.005.304182023-01-18
CVE-2023-21581 [MEDIUM] CWE-125 CVE-2023-21581: Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.3041
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interacti
nvd
CVE-2023-38236P4MEDIUMCVSS 5.5≥ 20.001.30005, < 20.005.30516.10516≥ 20.001.30005, < 20.005.30514.10514+1 more2023-08-10
CVE-2023-38236 [MEDIUM] CWE-125 CVE-2023-38236: Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must ope
nvd
CVE-2023-44360P4MEDIUMCVSS 5.5≥ 20.001.30005, < 20.005.30539≤ 23.006.203602023-11-16
CVE-2023-44360 [MEDIUM] CWE-125 CVE-2023-44360: Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected
Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must ope
nvd
CVE-2023-44348P4MEDIUMCVSS 5.5≥ 20.001.30005, < 20.005.30539≤ 23.006.203602023-11-16
CVE-2023-44348 [MEDIUM] CWE-125 CVE-2023-44348: Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected
Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must ope
nvd
CVE-2014-8451P4MEDIUMCVSS 5.0v10.0v10.0.1+25 more2014-12-10
CVE-2014-8451 [MEDIUM] CVE-2014-8451: An unspecified JavaScript API in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.1
An unspecified JavaScript API in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2014-8448.
nvd
CVE-2014-8448P4MEDIUMCVSS 5.0v10.0v10.0.1+25 more2014-12-10
CVE-2014-8448 [MEDIUM] CWE-200 CVE-2014-8448: An unspecified JavaScript API in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.1
An unspecified JavaScript API in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2014-8451.
nvd
CVE-2023-38244P4MEDIUMCVSS 5.5≥ 20.001.30005, < 20.005.30516.10516≥ 20.001.30005, < 20.005.30514.10514+1 more2023-08-10
CVE-2023-38244 [MEDIUM] CWE-125 CVE-2023-38244: Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must ope
nvd
CVE-2023-38242P4MEDIUMCVSS 5.5≥ 20.001.30005, < 20.005.30516.10516≥ 20.001.30005, < 20.005.30514.10514+1 more2023-08-10
CVE-2023-38242 [MEDIUM] CWE-125 CVE-2023-38242: Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must ope
nvd