cbcvebase.

Adobe Acrobat Reader vulnerabilities

1,132 known vulnerabilities affecting adobe/acrobat_reader.

Total CVEs
1,132
CISA KEV
22
actively exploited
Public exploits
46
Exploited in wild
42
Severity breakdown
CRITICAL350HIGH432MEDIUM321LOW29

Vulnerabilities

Page 56 of 57
CVE-2021-40729P4LOWCVSS 3.3≥ 20.001.30005, ≤ 20.004.30015≥ 17.011.30158, ≤ 17.011.30202+1 more2021-10-15
CVE-2021-40729 [LOW] CWE-125 CVE-2021-40729: Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 (and earlier), and 17.011.30202 (and earlier) is affected by a out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this iss
nvd
CVE-2005-1347P4LOWCVSS 2.6v3.0v5.0.10+1 more2005-05-02
CVE-2005-1347 [LOW] CVE-2005-1347: ** UNVERIFIABLE ** NOTE: this issue describes a problem that can not be independently verified as o ** UNVERIFIABLE ** NOTE: this issue describes a problem that can not be independently verified as of 20050421. Adobe Acrobat reader (AcroRd32.exe) 6.0 and earlier allows remote attackers to cause a denial of service ("Invalid-ID-Handle-Error" error) and modify memory beginning at a particular address, possibly allowing the execution of arbitrary code, via a craft
nvd
CVE-2021-35988P4LOWCVSS 3.3≥ unspecified, ≤ 2020.004.300052021-08-20
CVE-2021-35988 [LOW] CWE-125 CVE-2021-35988: Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the context of the current user. Exploitation of this issue requires user in
nvd
CVE-2021-35987P4LOWCVSS 3.3≥ unspecified, ≤ 2020.004.300052021-08-20
CVE-2021-35987 [LOW] CWE-125 CVE-2021-35987: Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the context of the current user. Exploitation of this issue requires user in
nvd
CVE-2025-54255P4MEDIUMCVSS 4.0≥ 20.001.30002, < 20.005.30791≤ 25.001.206722025-09-09
CVE-2025-54255 [MEDIUM] CWE-657 CVE-2025-54255: Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Viola Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Violation of Secure Design Principles vulnerability that could result in a security feature bypass impacting integrity. An attacker does not have to be authenticated. Exploitation of this issue does not require user interaction, and scope is unchanged.
nvd
CVE-2002-0030P4MEDIUMCVSS 4.6v4.0v4.0.5+4 more2003-04-02
CVE-2002-0030 [MEDIUM] CVE-2002-0030: The digital signature mechanism for the Adobe Acrobat PDF viewer only verifies the PE header of exec The digital signature mechanism for the Adobe Acrobat PDF viewer only verifies the PE header of executable code for a plug-in, which can allow attackers to execute arbitrary code in certified mode by making the plug-in appear to be signed by Adobe.
nvd
CVE-2020-24438P4LOWCVSS 3.3≤ 20.001.30005≥ unspecified, ≤ 2017.011.301752020-11-05
CVE-2020-24438 [LOW] CWE-416 CVE-2020-24438: Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a use-after-free vulnerability that could result in a memory address leak. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2023-29299P4MEDIUMCVSS 4.7≥ 20.001.30005, < 20.005.30516.10516≥ 20.001.30005, < 20.005.30514.10514+1 more2023-08-10
CVE-2023-29299 [MEDIUM] CWE-426 CVE-2023-29299: Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Untrusted Search Path vulnerability that could lead to Application denial-of-service. An attacker could leverage this vulnerability if the default PowerShell Set-ExecutionPolicy is set to Unrestricted, making the attack complexity high. Exploit
nvd
CVE-2021-40730P4LOWCVSS 3.3≥ 20.001.30005, ≤ 20.004.30015≥ 17.011.30158, ≤ 17.011.30202+1 more2021-10-15
CVE-2021-40730 [LOW] CWE-416 CVE-2021-40730: Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 (and earlier), and 17.011.30202 (and earlier) is affected by a use-after-free that allow a remote attacker to disclose sensitive information on affected installations of of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerabil
nvd
CVE-2021-39858P4LOWCVSS 3.3≥ 20.001.30005, ≤ 20.004.30006≥ unspecified, ≤ DC 2021 July2021-09-29
CVE-2021-39858 [LOW] CWE-125 CVE-2021-39858: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal
nvd
CVE-2021-21089P4LOWCVSS 3.3≥ unspecified, ≤ 2020.013.200742021-09-30
CVE-2021-21089 [LOW] CWE-125 CVE-2021-21089: Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2 Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to locally escalate privileges in the context of the current user. Exploitation of this issue requires user int
nvd
CVE-2009-2987P4MEDIUMCVSS 4.3≤ 9.1.3v7.0+24 more2009-10-19
CVE-2009-2987 [MEDIUM] CVE-2009-2987: Unspecified vulnerability in an ActiveX control in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x be Unspecified vulnerability in an ActiveX control in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 on Windows allows remote attackers to cause a denial of service via unknown vectors.
nvd
CVE-2020-24434P4LOWCVSS 3.3≤ 20.001.30005≥ unspecified, ≤ 2017.011.301752020-11-05
CVE-2020-24434 [LOW] CWE-125 CVE-2020-24434: Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interacti
nvd
CVE-2020-24426P4LOWCVSS 3.3≤ 20.001.30005≥ unspecified, ≤ 2017.011.301752020-11-05
CVE-2020-24426 [LOW] CWE-125 CVE-2020-24426: Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interacti
nvd
CVE-2021-28643P4LOWCVSS 3.3≥ unspecified, ≤ 2020.004.300052021-08-20
CVE-2021-28643 [LOW] CWE-843 CVE-2021-28643: Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.3 Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Type Confusion vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue requires user interac
nvd
CVE-2003-0142P4MEDIUMCVSS 5.0v6.02003-08-18
CVE-2003-0142 [MEDIUM] CVE-2003-0142: Adobe Acrobat Reader (acroread) 6, under certain circumstances when running with the "Certified plug Adobe Acrobat Reader (acroread) 6, under certain circumstances when running with the "Certified plug-ins only" option disabled, loads plug-ins with signatures used for older versions of Acrobat, which can allow attackers to cause Acrobat to enter Certified mode and run untrusted plugins by modifying the CTIsCertifiedMode function.
nvd
CVE-2001-1069P4HIGHCVSS 7.2v4.0.52001-08-31
CVE-2001-1069 [HIGH] CVE-2001-1069: libCoolType library as used in Adobe Acrobat (acroread) on Linux creates the AdobeFnt.lst file with libCoolType library as used in Adobe Acrobat (acroread) on Linux creates the AdobeFnt.lst file with world-writable permissions, which allows local users to modify the file and possibly modify acroread's behavior.
nvd
CVE-2020-24427P4LOWCVSS 3.3≤ 20.001.30005≥ unspecified, ≤ 2017.011.301752020-11-05
CVE-2020-24427 [LOW] CWE-20 CVE-2020-24427: Acrobat Reader versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.3017 Acrobat Reader versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by an input validation vulnerability when decoding a crafted codec that could result in the disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this
nvd
CVE-2021-21061P4LOWCVSS 3.3≥ 17.0, ≤ 17.011.30188≥ 20.0, ≤ 20.001.300183+1 more2021-02-11
CVE-2021-21061 [LOW] CWE-416 CVE-2021-21061: Acrobat Pro DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017 Acrobat Pro DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a Use-after-free vulnerability when parsing a specially crafted PDF file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploit
nvd
CVE-2022-24101P4LOWCVSS 3.3≥ 17.011.30059, ≤ 17.012.30205≥ 20.001.30005, ≤ 20.005.30314+2 more2022-05-11
CVE-2022-24101 [LOW] CWE-416 CVE-2022-24101: Acrobat Reader DC versions 20.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 ( Acrobat Reader DC versions 20.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that
nvd
Adobe Acrobat Reader vulnerabilities | cvebase