cbcvebase.

Adobe Acrobat Reader vulnerabilities

1,132 known vulnerabilities affecting adobe/acrobat_reader.

Total CVEs
1,132
CISA KEV
22
actively exploited
Public exploits
46
Exploited in wild
42
Severity breakdown
CRITICAL350HIGH432MEDIUM321LOW29

Vulnerabilities

Page 5 of 57
CVE-2021-39840P3HIGHCVSS 7.8≥ 20.001.30005, ≤ 20.004.30006≥ 17.011.30059, ≤ 17.011.30199+1 more2021-09-29
CVE-2021-39840 [HIGH] CWE-416 CVE-2021-39840: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability when processing AcroForms that could result in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability in that the target m
nvd
CVE-2017-11263P3HIGHCVSS 8.8≥ 17.011.00000, ≤ 17.011.300662017-08-11
CVE-2017-11263 [HIGH] CWE-119 CVE-2017-11263: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the internal data structure manipulation related to document encoding. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2007-0044P4MEDIUMCVSS 4.3PoC≤ 7.0.8v6.0+14 more2007-01-03
CVE-2007-0044 [MEDIUM] CWE-352 CVE-2007-0044: Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."
nvd
CVE-2018-4890P3HIGHCVSS 8.8≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4890 [HIGH] CWE-787 CVE-2018-4890: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability is an instance of a heap overflow vulnerability in the image conversion engine, when handling JPEG data embedded within an XPS file. A successful attack can lead to code corrupti
nvd
CVE-2010-2889P3CRITICALCVSS 9.3v8.0v8.1+22 more2010-10-06
CVE-2010-2889 [CRITICAL] CWE-20 CVE-2010-2889: Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Window Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execute arbitrary code via a crafted font, a different vulnerability than CVE-2010-3626.
nvd
CVE-2017-11211P3HIGHCVSS 8.8≥ 17.011.00000, ≤ 17.011.300662017-08-11
CVE-2017-11211 [HIGH] CWE-119 CVE-2017-11211: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in the JPEG parser. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2018-4910P3HIGHCVSS 8.8≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4910 [HIGH] CWE-787 CVE-2018-4910: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability is an instance of a heap overflow vulnerability in the JavaScript engine. The vulnerability is triggered by a PDF file with crafted JavaScript code that manipulates the optional
nvd
CVE-2021-44708P3HIGHCVSS 7.8≥ 17.011.30059, ≤ 17.011.30204≥ 20.001.30005, ≤ 20.004.30017+1 more2022-01-14
CVE-2021-44708 [HIGH] CWE-122 CVE-2021-44708: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a heap overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vi
nvd
CVE-2018-4872P3CRITICALCVSS 10.0≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4872 [CRITICAL] CVE-2018-4872: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability is a security bypass vulnerability that leads to a sandbox escape. Specifically, the vulnerability exists in the way a cross call is handled.
nvd
CVE-2011-0567P3CRITICALCVSS 9.3v8.0v8.1+25 more2011-02-10
CVE-2011-0567 [CRITICAL] CVE-2011-0567: AcroRd32.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 AcroRd32.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted image that triggers an incorrect pointer calculation, leading to heap memory corruption, a different vulnerability than CVE-
nvd
CVE-2018-4895P3CRITICALCVSS 9.8≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4895 [CRITICAL] CWE-787 CVE-2018-4895: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the image conversion engine when processing Enhanced Metafile For
nvd
CVE-2021-28558P3HIGHCVSS 8.8≥ 17.011.30059, ≤ 17.011.30194≥ 20.001.30005, ≤ 20.001.30020+1 more2021-09-02
CVE-2021-28558 [HIGH] CWE-122 CVE-2021-28558: Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2 Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Heap-based buffer overflow vulnerability in the PDFLibTool component. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Ex
nvd
CVE-2007-0103P3MEDIUMCVSS 6.8PoC≤ 7.0.82007-01-09
CVE-2007-0103 [MEDIUM] CWE-20 CVE-2007-0103: The Adobe PDF specification 1.3, as implemented by Adobe Acrobat before 8.0.0, allows remote attacke The Adobe PDF specification 1.3, as implemented by Adobe Acrobat before 8.0.0, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree
nvd
CVE-2017-16368P3HIGHCVSS 8.8≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16368 [HIGH] CWE-119 CVE-2017-16368: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability leads to a stack-based buffer overflow condition in the internal Unicode string manipulation module. It is triggered by an invalid PDF f
nvd
CVE-2014-8449P3CRITICALCVSS 10.0v10.0v10.0.1+25 more2014-12-10
CVE-2014-8449 [CRITICAL] CWE-189 CVE-2014-8449: Integer overflow in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows Integer overflow in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2017-16393P3HIGHCVSS 8.8≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16393 [HIGH] CWE-416 CVE-2017-16393: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the JavaScript engine. The mismatch between an old and a new object can provide an a
nvd
CVE-2018-4901P3HIGHCVSS 8.8≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4901 [HIGH] CWE-787 CVE-2018-4901: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the document identity representation. An attacker can potentially lev
nvd
CVE-1999-1576P3HIGHCVSS 7.5PoCv4.01999-09-27
CVE-1999-1576 [HIGH] CVE-1999-1576: Buffer overflow in Adobe Acrobat ActiveX control (pdf.ocx, PDF.PdfCtrl.1) 1.3.188 for Acrobat Reader Buffer overflow in Adobe Acrobat ActiveX control (pdf.ocx, PDF.PdfCtrl.1) 1.3.188 for Acrobat Reader 4.0 allows remote attackers to execute arbitrary code via the pdf.setview method.
nvd
CVE-2014-9160P3CRITICALCVSS 10.0v10.1.0v10.1.1+23 more2015-05-13
CVE-2014-9160 [CRITICAL] CWE-119 CVE-2014-9160: Multiple heap-based buffer overflows in Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before Multiple heap-based buffer overflows in Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to execute arbitrary code via unknown vectors.
nvd
CVE-2017-16385P3HIGHCVSS 8.8≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16385 [HIGH] CWE-119 CVE-2017-16385: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an incorrect length value in TIFF parsing during XPS conversion. Crafted TIFF image input causes a mism
nvd
Adobe Acrobat Reader vulnerabilities | cvebase