cbcvebase.

Adobe Acrobat Reader vulnerabilities

1,132 known vulnerabilities affecting adobe/acrobat_reader.

Total CVEs
1,132
CISA KEV
22
actively exploited
Public exploits
46
Exploited in wild
42
Severity breakdown
CRITICAL350HIGH432MEDIUM321LOW29

Vulnerabilities

Page 55 of 57
CVE-2011-1353P4MEDIUMCVSS 6.9v10.0v10.0.1+3 more2011-09-15
CVE-2011-1353 [MEDIUM] CVE-2011-1353: Unspecified vulnerability in Adobe Reader 10.x before 10.1.1 on Windows allows local users to gain p Unspecified vulnerability in Adobe Reader 10.x before 10.1.1 on Windows allows local users to gain privileges via unknown vectors.
nvd
CVE-2011-0570P4MEDIUMCVSS 6.9v8.0v8.1+25 more2011-02-10
CVE-2011-0570 [MEDIUM] CVE-2011-0570: Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2 Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than CVE-2011-0562 and CVE-2011-0588.
nvd
CVE-2011-0588P4MEDIUMCVSS 6.9v8.0v8.1+25 more2011-02-10
CVE-2011-0588 [MEDIUM] CVE-2011-0588: Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2 Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than CVE-2011-0562 and CVE-2011-0570.
nvd
CVE-2022-28252P4LOWCVSS 3.3≥ 17.011.30059, ≤ 17.012.30205≥ 20.001.30005, ≤ 20.005.30314+2 more2022-05-11
CVE-2022-28252 [LOW] CWE-125 CVE-2022-28252: Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (a Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exp
nvd
CVE-2007-5666P4MEDIUMCVSS 6.2≤ 8.1.12008-02-12
CVE-2007-5666 [MEDIUM] CWE-94 CVE-2007-5666: Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.1 and earlier allows local users Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.1 and earlier allows local users to execute arbitrary code via a malicious Security Provider library in the reader's current working directory. NOTE: this issue might be subsumed by CVE-2008-0655.
nvd
CVE-2010-3656P4MEDIUMCVSS 4.3v8.0v8.1+22 more2010-10-06
CVE-2010-3656 [MEDIUM] CVE-2010-3656: Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Window Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2010-3657.
nvd
CVE-2010-3657P4MEDIUMCVSS 4.3v8.0v8.1+22 more2010-10-06
CVE-2010-3657 [MEDIUM] CVE-2010-3657: Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Window Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2010-3656.
nvd
CVE-2011-2104P4MEDIUMCVSS 4.3v8.0v8.1+33 more2011-06-16
CVE-2011-2104 [MEDIUM] CWE-119 CVE-2011-2104: Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac O Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allow attackers to cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2024-49531P4MEDIUMCVSS 5.5≥ 20.001.30002, < 20.005.30748≤ 20.005.307102024-12-10
CVE-2024-49531 [MEDIUM] CWE-476 CVE-2024-49531: Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and ear Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this
nvd
CVE-2008-4816P4MEDIUMCVSS 4.3≤ 8.02008-11-05
CVE-2008-4816 [MEDIUM] CVE-2008-4816: Unspecified vulnerability in the Download Manager in Adobe Reader 8.1.2 and earlier on Windows allow Unspecified vulnerability in the Download Manager in Adobe Reader 8.1.2 and earlier on Windows allows remote attackers to change Internet Security options on a client machine via unknown vectors.
nvd
CVE-2025-47111P4MEDIUMCVSS 5.5≥ 20.0, < 20.005.30774≤ 25.001.205212025-06-10
CVE-2025-47111 [MEDIUM] CWE-476 CVE-2025-47111: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a NULL Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing a disruption in service. Exploitation of this issue requires user interaction in that a v
nvd
CVE-2009-2979P4MEDIUMCVSS 4.3≤ 9.1.3v7.0+24 more2009-10-19
CVE-2009-2979 [MEDIUM] CVE-2009-2979: Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 do not pro Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 do not properly perform XMP-XML entity expansion, which allows remote attackers to cause a denial of service via a crafted document.
nvd
CVE-2010-0190P4MEDIUMCVSS 4.3v9.0v9.1+15 more2010-04-14
CVE-2010-0190 [MEDIUM] CWE-79 CVE-2010-0190: Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x befor Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2022-28269P4LOWCVSS 3.3≥ 17.011.30059, ≤ 17.012.30205≥ 20.001.30005, ≤ 20.005.30314+2 more2022-05-11
CVE-2022-28269 [LOW] CWE-416 CVE-2022-28269: Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 ( Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of Annotation objects that could result in a memory leak in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a m
nvd
CVE-2020-24431P4MEDIUMCVSS 4.4≤ 20.001.30005≥ unspecified, ≤ 2017.011.301752020-11-05
CVE-2020-24431 [MEDIUM] CWE-285 CVE-2020-24431: Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) for macOS are affected by a security feature bypass that could result in dynamic library code injection by the Adobe Reader process. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2021-39844P4LOWCVSS 3.3≥ 20.001.30005, ≤ 20.004.30006≥ 17.011.30059, ≤ 17.011.30199+1 more2021-09-29
CVE-2021-39844 [LOW] CWE-125 CVE-2021-39844: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal
nvd
CVE-2021-35986P4LOWCVSS 3.3≥ unspecified, ≤ 2020.004.300052021-08-20
CVE-2021-35986 [LOW] CWE-843 CVE-2021-35986: Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Type Confusion vulnerability. An unauthenticated attacker could leverage this vulnerability to read arbitrary system information in the context of the current user. Exploitation of this issue requires user interactio
nvd
CVE-2009-2992P4MEDIUMCVSS 4.3≤ 9.1.3v7.0+24 more2009-10-19
CVE-2009-2992 [MEDIUM] CWE-20 CVE-2009-2992: An unspecified ActiveX control in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and pos An unspecified ActiveX control in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 does not properly validate input, which allows attackers to cause a denial of service via unknown vectors.
nvd
CVE-2009-2988P4MEDIUMCVSS 4.3v7.0v7.0.1+24 more2009-10-19
CVE-2009-2988 [MEDIUM] CWE-20 CVE-2009-2988: Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly vali Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which allows attackers to cause a denial of service via unspecified vectors.
nvd
CVE-2006-0525P4MEDIUMCVSS 4.6v3.0v4.0+17 more2006-02-02
CVE-2006-0525 [MEDIUM] CWE-264 CVE-2006-0525: Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center, install a large number of .EXE and .DLL files with write-access permission for the Everyone group, which allows local users to gain privileges via Trojan horse programs.
nvd
Adobe Acrobat Reader vulnerabilities | cvebase