cbcvebase.

Adobe Acrobat Reader vulnerabilities

1,132 known vulnerabilities affecting adobe/acrobat_reader.

Total CVEs
1,132
CISA KEV
22
actively exploited
Public exploits
46
Exploited in wild
42
Severity breakdown
CRITICAL350HIGH432MEDIUM321LOW29

Vulnerabilities

Page 57 of 57
CVE-2022-28268P4LOWCVSS 3.3≥ 17.011.30059, ≤ 17.012.30205≥ 20.001.30005, ≤ 20.005.30314+2 more2022-05-11
CVE-2022-28268 [LOW] CWE-125 CVE-2022-28268: Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 ( Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in
nvd
CVE-2015-7829P4LOWCVSS 1.9≥ 10.0, ≤ 10.1.15≥ 11.0.0, ≤ 11.0.122015-10-15
CVE-2015-7829 [LOW] CVE-2015-7829: Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows mishandle junctions in the Synchronizer directory, which allows attackers to delete arbitrary files via Adobe Collaboration Sync, a related issue to CVE-201
nvd
CVE-2021-21046P4LOWCVSS 3.3≥ 17.0, ≤ 17.011.30188≥ 20.0, ≤ 20.001.300183+1 more2021-02-11
CVE-2021-21046 [LOW] CWE-787 CVE-2021-21046: Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2 Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to cause an application denial-of-service. Exploitation of this issue requires user interaction in that a victim
nvd
CVE-2025-64787P4LOWCVSS 3.3≥ 20.001.3005, < 20.005.30838≤ 20.005.308032025-12-09
CVE-2025-64787 [LOW] CWE-347 CVE-2025-64787: Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and ear Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass cryptographic protections and gain limited unauthorized write a
nvd
CVE-2025-64786P4LOWCVSS 3.3≥ 20.001.3005, < 20.005.30838≤ 20.005.308032025-12-09
CVE-2025-64786 [LOW] CWE-347 CVE-2025-64786: Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and ear Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain limited unauthorized write access. Exploitation of this issue req
nvd
CVE-2006-3452P4MEDIUMCVSS 4.6≤ 6.0.4v3.0+12 more2006-07-12
CVE-2006-3452 [MEDIUM] CVE-2006-3452: Adobe Reader and Acrobat 6.0.4 and earlier, on Mac OSX, has insecure file and directory permissions, Adobe Reader and Acrobat 6.0.4 and earlier, on Mac OSX, has insecure file and directory permissions, which allows local users to gain privileges by overwriting program files.
nvd
CVE-2021-44714P4LOWCVSS 3.3≥ 17.011.30059, ≤ 17.011.30204≥ 20.001.30005, ≤ 20.004.30017+1 more2022-01-14
CVE-2021-44714 [LOW] CWE-657 CVE-2021-44714: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a Violation of Secure Design Principles that could lead to a Security feature bypass. Acrobat Reader DC displays a warning message when a user clicks on a PDF file, which could be used by an attacker to mislead the user. In af
nvd
CVE-2008-0883P4LOWCVSS 3.7v8.1.22008-03-06
CVE-2008-0883 [LOW] CWE-59 CVE-2008-0883: acroread in Adobe Acrobat Reader 8.1.2 allows local users to overwrite arbitrary files via a symlink acroread in Adobe Acrobat Reader 8.1.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files related to SSL certificate handling.
nvd
CVE-2020-24439P4LOWCVSS 2.8≤ 20.001.30005≥ unspecified, ≤ 2017.011.301752020-11-05
CVE-2020-24439 [LOW] CWE-347 CVE-2020-24439: Acrobat Reader DC for macOS versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and Acrobat Reader DC for macOS versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a security feature bypass. While the practical security impact is minimal, a defense-in-depth fix has been implemented to further harden the Adobe Reader update process.
nvd
CVE-2002-1764P4LOWCVSS 2.1v4.0.52002-12-31
CVE-2002-1764 [LOW] CVE-2002-1764: acroread in Adobe Acrobat Reader 4.05 on Linux allows local users to overwrite arbitrary files via a acroread in Adobe Acrobat Reader 4.05 on Linux allows local users to overwrite arbitrary files via a symlink attack on temporary files.
nvd
CVE-2005-0492P4LOWCVSS 2.6v6.0.3v7.02005-05-02
CVE-2005-0492 [LOW] CWE-20 CVE-2005-0492: Adobe Acrobat Reader 6.0.3 and 7.0.0 allows remote attackers to cause a denial of service (applicati Adobe Acrobat Reader 6.0.3 and 7.0.0 allows remote attackers to cause a denial of service (application crash) via a PDF file that contains a negative Count value in the root page node.
nvd
CVE-2005-1841P4LOWCVSS 2.1v5.0.9v5.0.102005-07-07
CVE-2005-1841 [LOW] CVE-2005-1841: The control for Adobe Reader 5.0.9 and 5.0.10 on Linux, Solaris, HP-UX, and AIX creates temporary fi The control for Adobe Reader 5.0.9 and 5.0.10 on Linux, Solaris, HP-UX, and AIX creates temporary files with the permissions as specified in a user's umask, which could allow local users to read PDF documents of that user if the umask allows it.
nvd
Adobe Acrobat Reader vulnerabilities | cvebase