Adobe Acrobat Reader vulnerabilities
1,132 known vulnerabilities affecting adobe/acrobat_reader.
Total CVEs
1,132
CISA KEV
22
actively exploited
Public exploits
46
Exploited in wild
42
Severity breakdown
CRITICAL350HIGH432MEDIUM321LOW29
Vulnerabilities
Page 54 of 57
CVE-2026-27221P4MEDIUMCVSS 5.5≤ 25.001.212652026-03-10
CVE-2026-27221 [MEDIUM] CWE-295 CVE-2026-27221: Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Impr
Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to spoof the identity of a signer. Exploitation of this issue requires user interaction.
nvd
CVE-2021-21034P4MEDIUMCVSS 4.3≥ 17.0, ≤ 17.011.30188≥ 20.0, ≤ 20.001.300183+1 more2021-02-11
CVE-2021-21034 [MEDIUM] CWE-125 CVE-2021-21034: Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to locally elevate privileges in the context of the current user. Exploitation of this issue requires user i
nvd
CVE-2005-0035P4MEDIUMCVSS 5.1v4.5v5.0+7 more2005-05-02
CVE-2005-0035 [MEDIUM] CVE-2005-0035: The Acrobat web control in Adobe Acrobat and Acrobat Reader 7.0 and earlier, when used with Internet
The Acrobat web control in Adobe Acrobat and Acrobat Reader 7.0 and earlier, when used with Internet Explorer, allows remote attackers to determine the existence of arbitrary files via the LoadFile ActiveX method.
nvd
CVE-2013-2737P4MEDIUMCVSS 5.0v9.0v9.1+36 more2013-05-16
CVE-2013-2737 [MEDIUM] CWE-200 CVE-2013-2737: A JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 1
A JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2021-44712P4MEDIUMCVSS 5.5≥ 17.011.30059, ≤ 17.011.30204≥ 20.001.30005, ≤ 20.004.30017+1 more2022-01-14
CVE-2021-44712 [MEDIUM] CWE-788 CVE-2021-44712: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an Access of Memory Location After End of Buffer vulnerability that could lead to application denial-of-service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2015-6704P4MEDIUMCVSS 4.3≥ 10.0, ≤ 10.1.15≥ 11.0.0, ≤ 11.0.122015-10-14
CVE-2015-6704 [MEDIUM] CVE-2015-6704: The animations property implementation in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x befo
The animations property implementation in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to obtain sensitive information from process memory via a function call, a different
nvd
CVE-2015-6701P4MEDIUMCVSS 4.3≥ 10.0, ≤ 10.1.15≥ 11.0.0, ≤ 11.0.122015-10-14
CVE-2015-6701 [MEDIUM] CVE-2015-6701: The ambientIlluminationColor property implementation in Adobe Reader and Acrobat 10.x before 10.1.16
The ambientIlluminationColor property implementation in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to obtain sensitive information from process memory via a function cal
nvd
CVE-2015-5107P4MEDIUMCVSS 4.3≥ 10.0, < 10.1.15≥ 11.0.0, < 11.0.122015-07-15
CVE-2015-5107 [MEDIUM] CWE-200 CVE-2015-5107: Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2014-0562P4MEDIUMCVSS 4.3v10.0v10.0.1+23 more2014-09-17
CVE-2014-0562 [MEDIUM] CWE-79 CVE-2014-0562: Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x be
Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on OS X allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)."
nvd
CVE-2021-44739P4MEDIUMCVSS 4.3≥ 20.001.30005, ≤ 20.004.30017≥ 17.011.30180, ≤ 17.011.30204+1 more2022-01-14
CVE-2021-44739 [MEDIUM] CWE-200 CVE-2021-44739: Acrobat Reader DC ActiveX Control versions 21.007.20099 (and earlier), 20.004.30017 (and earlier) an
Acrobat Reader DC ActiveX Control versions 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obtain NTLMv2 credentials. Exploitation of this issue requires user interaction in that a victim mus
nvd
CVE-2021-28557P4MEDIUMCVSS 4.3≥ 17.011.30059, ≤ 17.011.30194≥ 20.001.30005, ≤ 20.001.30020+1 more2021-09-02
CVE-2021-28557 [MEDIUM] CWE-125 CVE-2021-28557: Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to leak sensitive system information in the context of the current user. Exploitation of this issue requires
nvd
CVE-2004-1598P4MEDIUMCVSS 5.0v6.0v6.0.1+1 more2004-10-12
CVE-2004-1598 [MEDIUM] CVE-2004-1598: Adobe Acrobat and Acrobat Reader 6.0 allow remote attackers to read arbitrary files via a PDF file t
Adobe Acrobat and Acrobat Reader 6.0 allow remote attackers to read arbitrary files via a PDF file that contains an embedded Shockwave (swf) file that references files outside of the temporary directory.
nvd
CVE-2021-39857P4MEDIUMCVSS 4.3≥ 17.011.30059, ≤ 17.011.30199≥ 20.001.30005, ≤ 20.004.30006+1 more2021-09-29
CVE-2021-39857 [MEDIUM] CWE-200 CVE-2021-39857: Adobe Acrobat Reader DC add-on for Internet Explorer versions 2021.005.20060 (and earlier), 2020.004
Adobe Acrobat Reader DC add-on for Internet Explorer versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to check for existence of local files. Exploitation of this issue requires use
nvd
CVE-2021-44702P4MEDIUMCVSS 4.3≥ 20.001.30005, ≤ 20.004.30017≥ 17.011.30180, ≤ 17.011.30204+1 more2022-01-14
CVE-2021-44702 [MEDIUM] CWE-200 CVE-2021-44702: Acrobat Reader DC ActiveX Control versions 21.007.20099 (and earlier), 20.004.30017 (and earlier) an
Acrobat Reader DC ActiveX Control versions 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obtain NTLMv2 credentials. Exploitation of this issue requires user interaction in that a victim mus
nvd
CVE-2011-0562P4MEDIUMCVSS 6.9v8.0v8.1+25 more2011-02-10
CVE-2011-0562 [MEDIUM] CVE-2011-0562: Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2
Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than CVE-2011-0570 and CVE-2011-0588.
nvd
CVE-2026-47925P4MEDIUMCVSS 5.5≤ 26.001.216512026-06-09
CVE-2026-47925 [MEDIUM] CWE-190 CVE-2026-47925: Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Integer Overflow o
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in
nvd
CVE-2011-0604P4MEDIUMCVSS 4.3v8.0v8.1+25 more2011-02-10
CVE-2011-0604 [MEDIUM] CVE-2011-0604: Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before
Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-0587.
nvd
CVE-2011-0587P4MEDIUMCVSS 4.3v8.0v8.1+25 more2011-02-10
CVE-2011-0587 [MEDIUM] CWE-79 CVE-2011-0587: Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before
Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-0604.
nvd
CVE-2021-21060P4MEDIUMCVSS 4.6≥ 17.0, ≤ 17.011.30188≥ 20.0, ≤ 20.001.300183+1 more2021-02-11
CVE-2021-21060 [MEDIUM] CWE-20 CVE-2021-21060: Adobe Acrobat Pro DC versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.01
Adobe Acrobat Pro DC versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an improper input validation vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requires us
nvd
CVE-2011-2100P4MEDIUMCVSS 6.9v8.0v8.1+33 more2011-06-16
CVE-2011-2100 [MEDIUM] CVE-2011-2100: Untrusted search path vulnerability in Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, an
Untrusted search path vulnerability in Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory.
nvd