cbcvebase.

Adobe Acrobat Reader vulnerabilities

1,132 known vulnerabilities affecting adobe/acrobat_reader.

Total CVEs
1,132
CISA KEV
22
actively exploited
Public exploits
46
Exploited in wild
42
Severity breakdown
CRITICAL350HIGH432MEDIUM321LOW29

Vulnerabilities

Page 6 of 57
CVE-2017-16381P3HIGHCVSS 8.8≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16381 [HIGH] CWE-119 CVE-2017-16381: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an incorrect length value when processing TIFF files embedded within an XPS document. Crafted TIFF imag
nvd
CVE-2017-16396P3HIGHCVSS 8.8≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16396 [HIGH] CWE-119 CVE-2017-16396: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an incorrect length value in the TIFF processing module. Crafted input causes a mismatch between alloca
nvd
CVE-2017-16395P3HIGHCVSS 8.8≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16395 [HIGH] CWE-119 CVE-2017-16395: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an incorrect length value in the image conversion module when processing Enhanced Metafile Format (EMF)
nvd
CVE-2017-16392P3HIGHCVSS 8.8≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16392 [HIGH] CWE-119 CVE-2017-16392: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an incorrect length value in the JPEG processing module. Crafted input with an unexpected JPEG file seg
nvd
CVE-2009-3955P3CRITICALCVSS 10.0≤ 9.2v3.0+48 more2010-01-13
CVE-2009-3955 [CRITICAL] CWE-399 CVE-2009-3955: Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote a Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted JPC_MS_RGN marker in the Jp2c stream of a JpxDecode encoded data stream, which triggers an integer sign extension that bypasses a sanity check, leading to memory corruption.
nvd
CVE-2012-0774P3CRITICALCVSS 10.0v9.0v9.1+18 more2012-04-10
CVE-2012-0774 [CRITICAL] CWE-189 CVE-2012-0774: Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 allows attacker Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 allows attackers to execute arbitrary code via a crafted TrueType font.
nvd
CVE-2009-2564P3HIGHCVSS 7.2PoCv9.0v9.12009-07-21
CVE-2009-2564 [HIGH] CWE-264 CVE-2009-2564: NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versi NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus Download Manager before 1.5.0.48, and possibly other products, installs NOS\bin\getPlus_HelperSvc.exe with insecure permissions (Everyone:Full Control), which allows local users to gain SYSTEM privileges by replacing getPlus_HelperSvc.e
nvd
CVE-2013-3351P3CRITICALCVSS 10.0v10.0v10.0.1+14 more2013-09-12
CVE-2013-3351 [CRITICAL] CWE-119 CVE-2013-3351: Multiple stack-based buffer overflows in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0 Multiple stack-based buffer overflows in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allow attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2015-3048P3CRITICALCVSS 10.0v10.1.0v10.1.1+23 more2015-05-13
CVE-2015-3048 [CRITICAL] CWE-119 CVE-2015-3048: Buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows a Buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allows attackers to execute arbitrary code via unknown vectors.
nvd
CVE-2014-0527P3CRITICALCVSS 10.0v10.0v10.0.1+19 more2014-05-14
CVE-2014-0527 [CRITICAL] CWE-399 CVE-2014-0527: Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2021-44709P3HIGHCVSS 7.8≥ 17.011.30059, ≤ 17.011.30204≥ 20.001.30005, ≤ 20.004.30017+1 more2022-01-14
CVE-2021-44709 [HIGH] CWE-122 CVE-2021-44709: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a heap overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vi
nvd
CVE-2003-0508P3HIGHCVSS 7.5PoC≤ 5.0.72003-08-07
CVE-2003-0508 [HIGH] CVE-2003-0508: Buffer overflow in the WWWLaunchNetscape function of Adobe Acrobat Reader (acroread) 5.0.7 and earli Buffer overflow in the WWWLaunchNetscape function of Adobe Acrobat Reader (acroread) 5.0.7 and earlier allows remote attackers to execute arbitrary code via a .pdf file with a long mailto link.
nvd
CVE-2012-2049P3CRITICALCVSS 10.0v9.0v9.1+27 more2012-08-15
CVE-2012-2049 [CRITICAL] CWE-119 CVE-2012-2049: Stack-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on W Stack-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2012-2050P3CRITICALCVSS 10.0v9.0v9.1+27 more2012-08-15
CVE-2012-2050 [CRITICAL] CWE-119 CVE-2012-2050: Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and M Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2013-3357P3CRITICALCVSS 10.0v10.0v10.0.1+14 more2013-09-12
CVE-2013-3357 [CRITICAL] CWE-189 CVE-2013-3357: Integer overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Ma Integer overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-3358.
nvd
CVE-2013-3358P3CRITICALCVSS 10.0v11.0v11.0.1+14 more2013-09-12
CVE-2013-3358 [CRITICAL] CVE-2013-3358: Integer overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Ma Integer overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-3357.
nvd
CVE-2018-4916P3HIGHCVSS 8.8≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4916 [HIGH] CWE-787 CVE-2018-4916: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the image conversion module that handless TIFF data. An attacker can
nvd
CVE-2018-4915P3HIGHCVSS 8.8≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4915 [HIGH] CWE-787 CVE-2018-4915: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the JavaScript API related to color conversion. An attacker can poten
nvd
CVE-2018-4898P3HIGHCVSS 8.8≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4898 [HIGH] CWE-787 CVE-2018-4898: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the XPS engine that adds vector graphics and images to a fixed page.
nvd
CVE-2017-11241P3HIGHCVSS 8.8≥ 17.011.00000, ≤ 17.011.300662017-08-11
CVE-2017-11241 [HIGH] CWE-119 CVE-2017-11241: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to polygons. Successful exploitation could lead to arbitrary code execution.
nvd
Adobe Acrobat Reader vulnerabilities | cvebase