Adobe Acrobat Reader vulnerabilities

1,107 known vulnerabilities affecting adobe/acrobat_reader.

Total CVEs
1,107
CISA KEV
21
actively exploited
Public exploits
43
Exploited in wild
25
Severity breakdown
CRITICAL352HIGH412MEDIUM316LOW27

Vulnerabilities

Page 55 of 56
CVE-2006-6027CRITICALCVSS 9.3PoCv7.0v7.0.1+7 more2006-11-21
CVE-2006-6027 [CRITICAL] CVE-2006-6027: Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of s Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the LoadFile method in an AcroPDF ActiveX control.
nvd
CVE-2006-3452MEDIUMCVSS 4.6≤ 6.0.4v3.0+12 more2006-07-12
CVE-2006-3452 [MEDIUM] CVE-2006-3452: Adobe Reader and Acrobat 6.0.4 and earlier, on Mac OSX, has insecure file and directory permissions, Adobe Reader and Acrobat 6.0.4 and earlier, on Mac OSX, has insecure file and directory permissions, which allows local users to gain privileges by overwriting program files.
nvd
CVE-2006-3093MEDIUMCVSS 6.8v3.0v4.0+20 more2006-06-19
CVE-2006-3093 [MEDIUM] CVE-2006-3093: Multiple unspecified vulnerabilities in Adobe Acrobat Reader (acroread) before 7.0.8 have unknown im Multiple unspecified vulnerabilities in Adobe Acrobat Reader (acroread) before 7.0.8 have unknown impact and unknown vectors.
nvd
CVE-2006-1627HIGHCVSS 7.5≤ 6.02006-04-13
CVE-2006-1627 [HIGH] CVE-2006-1627: Adobe Document Server for Reader Extensions 6.0 does not provide proper access control, which allows Adobe Document Server for Reader Extensions 6.0 does not provide proper access control, which allows remote authenticated users to perform privileged actions by modifying the (1) actionID and (2) pageID parameters. NOTE: due to an error during reservation, this identifier was inadvertently associated with multiple issues. Other CVE identifiers have been assigne
nvd
CVE-2006-0525MEDIUMCVSS 4.6v3.0v4.0+17 more2006-02-02
CVE-2006-0525 [MEDIUM] CWE-264 CVE-2006-0525: Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center, install a large number of .EXE and .DLL files with write-access permission for the Everyone group, which allows local users to gain privileges via Trojan horse programs.
nvd
CVE-2005-2470HIGHCVSS 7.5v5.1v6.0+6 more2005-08-16
CVE-2005-2470 [HIGH] CVE-2005-2470: Buffer overflow in a "core application plug-in" for Adobe Reader 5.1 through 7.0.2 and Acrobat 5.0 t Buffer overflow in a "core application plug-in" for Adobe Reader 5.1 through 7.0.2 and Acrobat 5.0 through 7.0.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.
nvd
CVE-2005-1841LOWCVSS 2.1v5.0.9v5.0.102005-07-07
CVE-2005-1841 [LOW] CVE-2005-1841: The control for Adobe Reader 5.0.9 and 5.0.10 on Linux, Solaris, HP-UX, and AIX creates temporary fi The control for Adobe Reader 5.0.9 and 5.0.10 on Linux, Solaris, HP-UX, and AIX creates temporary files with the permissions as specified in a user's umask, which could allow local users to read PDF documents of that user if the umask allows it.
nvd
CVE-2005-1625MEDIUMCVSS 5.0v5.0.9v5.0.102005-07-05
CVE-2005-1625 [MEDIUM] CVE-2005-1625: Stack-based buffer overflow in the UnixAppOpenFilePerform function in Adobe Reader 5.0.9 and 5.0.10 Stack-based buffer overflow in the UnixAppOpenFilePerform function in Adobe Reader 5.0.9 and 5.0.10 for Unix allows remote attackers to execute arbitrary code via a PDF document with a long /Filespec tag.
nvd
CVE-2005-1306HIGHCVSS 7.5PoCv7.0v7.0.12005-06-15
CVE-2005-1306 [HIGH] CWE-611 CVE-2005-1306: The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determ The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."
nvd
CVE-2005-0035MEDIUMCVSS 5.1v4.5v5.0+7 more2005-05-02
CVE-2005-0035 [MEDIUM] CVE-2005-0035: The Acrobat web control in Adobe Acrobat and Acrobat Reader 7.0 and earlier, when used with Internet The Acrobat web control in Adobe Acrobat and Acrobat Reader 7.0 and earlier, when used with Internet Explorer, allows remote attackers to determine the existence of arbitrary files via the LoadFile ActiveX method.
nvd
CVE-2005-0492LOWCVSS 2.6v6.0.3v7.02005-05-02
CVE-2005-0492 [LOW] CWE-20 CVE-2005-0492: Adobe Acrobat Reader 6.0.3 and 7.0.0 allows remote attackers to cause a denial of service (applicati Adobe Acrobat Reader 6.0.3 and 7.0.0 allows remote attackers to cause a denial of service (application crash) via a PDF file that contains a negative Count value in the root page node.
nvd
CVE-2005-1347LOWCVSS 2.6v3.0v5.0.10+1 more2005-05-02
CVE-2005-1347 [LOW] CVE-2005-1347: ** UNVERIFIABLE ** NOTE: this issue describes a problem that can not be independently verified as o ** UNVERIFIABLE ** NOTE: this issue describes a problem that can not be independently verified as of 20050421. Adobe Acrobat reader (AcroRd32.exe) 6.0 and earlier allows remote attackers to cause a denial of service ("Invalid-ID-Handle-Error" error) and modify memory beginning at a particular address, possibly allowing the execution of arbitrary code, via a craf
nvd
CVE-2004-1152CRITICALCVSS 10.0v5.0.92005-01-10
CVE-2004-1152 [CRITICAL] CVE-2004-1152: Buffer overflow in the mailListIsPdf function in Adobe Acrobat Reader 5.09 for Unix allows remote at Buffer overflow in the mailListIsPdf function in Adobe Acrobat Reader 5.09 for Unix allows remote attackers to execute arbitrary code via an e-mail message with a crafted PDF attachment.
nvd
CVE-2004-1153CRITICALCVSS 10.0v6.0v6.0.2+1 more2005-01-10
CVE-2004-1153 [CRITICAL] CVE-2004-1153: Format string vulnerability in Adobe Acrobat Reader 6.0.0 through 6.0.2 allows remote attackers to c Format string vulnerability in Adobe Acrobat Reader 6.0.0 through 6.0.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an .ETD document containing format string specifiers in (1) title or (2) baseurl fields.
nvd
CVE-2004-1598MEDIUMCVSS 5.0v6.0v6.0.1+1 more2004-10-12
CVE-2004-1598 [MEDIUM] CVE-2004-1598: Adobe Acrobat and Acrobat Reader 6.0 allow remote attackers to read arbitrary files via a PDF file t Adobe Acrobat and Acrobat Reader 6.0 allow remote attackers to read arbitrary files via a PDF file that contains an embedded Shockwave (swf) file that references files outside of the temporary directory.
nvd
CVE-2004-0629HIGHCVSS 7.5v5.0v5.0.5+4 more2004-09-28
CVE-2004-0629 [HIGH] CVE-2004-0629: Buffer overflow in the ActiveX component (pdf.ocx) for Adobe Acrobat 5.0.5 and Acrobat Reader, and p Buffer overflow in the ActiveX component (pdf.ocx) for Adobe Acrobat 5.0.5 and Acrobat Reader, and possibly other versions, allows remote attackers to execute arbitrary code via a URI for a PDF file with a null terminator (%00) followed by a long string.
nvd
CVE-2004-0631CRITICALCVSS 10.0v5.0v5.0.5+1 more2004-08-18
CVE-2004-0631 [CRITICAL] CVE-2004-0631: Buffer overflow in the uudecoding feature for Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linu Buffer overflow in the uudecoding feature for Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arbitrary code via a long filename for the PDF file that is provided to the uudecode command.
nvd
CVE-2004-0630CRITICALCVSS 10.0v5.0v5.0.5+1 more2004-08-18
CVE-2004-0630 [CRITICAL] CVE-2004-0630: The uudecoding feature in Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly othe The uudecoding feature in Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arbitrary code via shell metacharacters ("`" or backtick) in the filename of the PDF file that is provided to the uudecode command.
nvd
CVE-2004-0632HIGHCVSS 7.5v6.0v6.0.12004-07-27
CVE-2004-0632 [HIGH] CVE-2004-0632: Adobe Reader 6.0 does not properly handle null characters when splitting a filename path into compon Adobe Reader 6.0 does not properly handle null characters when splitting a filename path into components, which allows remote attackers to execute arbitrary code via a file with a long extension that is not normally handled by Reader, triggering a buffer overflow.
nvd
CVE-2004-0194HIGHCVSS 7.5PoCv5.12004-03-29
CVE-2004-0194 [HIGH] CVE-2004-0194: Stack-based buffer overflow in the OutputDebugString function for Adobe Acrobat Reader 5.1 allows re Stack-based buffer overflow in the OutputDebugString function for Adobe Acrobat Reader 5.1 allows remote attackers to execute arbitrary code via a PDF document with XML Forms Data Format (XFDF) data.
nvd