cbcvebase.

Adobe Acrobat Reader vulnerabilities

1,132 known vulnerabilities affecting adobe/acrobat_reader.

Total CVEs
1,132
CISA KEV
22
actively exploited
Public exploits
46
Exploited in wild
42
Severity breakdown
CRITICAL350HIGH432MEDIUM321LOW29

Vulnerabilities

Page 9 of 57
CVE-2009-3959P3CRITICALCVSS 10.0≤ 9.2v3.0+48 more2010-01-13
CVE-2009-3959 [CRITICAL] CWE-189 CVE-2009-3959: Integer overflow in the U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, and 8.x befor Integer overflow in the U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a malformed PDF document.
nvd
CVE-2013-0610P3CRITICALCVSS 10.0v9.0v9.1+30 more2013-01-10
CVE-2013-0610 [CRITICAL] CWE-119 CVE-2013-0610: Stack-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11 Stack-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0626.
nvd
CVE-2018-4892P3HIGHCVSS 8.8≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4892 [HIGH] CWE-416 CVE-2018-4892: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the JBIG2 decoder. The vulnerability is triggered by a crafted PDF file that contains a malformed JBIG2 stream. Successful exp
nvd
CVE-2014-0511P3CRITICALCVSS 10.0v11.0.62014-03-27
CVE-2014-0511 [CRITICAL] CWE-119 CVE-2014-0511: Heap-based buffer overflow in Adobe Reader 11.0.06 allows remote attackers to execute arbitrary code Heap-based buffer overflow in Adobe Reader 11.0.06 allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.
nvd
CVE-2017-16398P3CRITICALCVSS 9.8≤ 11.0.22≥ 17.0, ≤ 17.011.300662017-12-09
CVE-2017-16398 [CRITICAL] CWE-416 CVE-2017-16398: An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.3 An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the JavaScript engine. The mismatch between an old and a new object can provide
nvd
CVE-2011-0598P3CRITICALCVSS 9.3v8.0v8.1+25 more2011-02-10
CVE-2011-0598 [CRITICAL] CVE-2011-0598: Integer overflow in ACE.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8. Integer overflow in ACE.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to execute arbitrary code via crafted ICC data, a different vulnerability than CVE-2011-0596, CVE-2011-0599, and CVE-2011-0602.
nvd
CVE-2013-0626P3CRITICALCVSS 10.0v9.0v9.1+30 more2013-01-10
CVE-2013-0626 [CRITICAL] CVE-2013-0626: Stack-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11 Stack-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0610.
nvd
CVE-2018-4911P3HIGHCVSS 8.8≥ 17.0, ≤ 17.011.300702018-02-27
CVE-2018-4911 [HIGH] CWE-416 CVE-2018-4911: An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the JavaScript API related to bookmark functionality. The vulnerability is triggered by crafted JavaScript code embedded withi
nvd
CVE-2021-28565P3HIGHCVSS 8.8≥ 17.011.30059, ≤ 17.011.30194≥ 20.001.30005, ≤ 20.001.30020+1 more2021-09-02
CVE-2021-28565 [HIGH] CWE-125 CVE-2021-28565: Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2 Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Out-of-bounds Read vulnerability in the PDFLibTool component. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitati
nvd
CVE-2015-6683P3CRITICALCVSS 10.0≥ 10.0, ≤ 10.1.15≥ 11.0.0, ≤ 11.0.122015-10-14
CVE-2015-6683 [CRITICAL] CVE-2015-6683: Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13 Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5
nvd
CVE-2015-6684P3CRITICALCVSS 10.0≥ 10.0, ≤ 10.1.15≥ 11.0.0, ≤ 11.0.122015-10-14
CVE-2015-6684 [CRITICAL] CVE-2015-6684: Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13 Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5
nvd
CVE-2013-0611P3CRITICALCVSS 10.0v9.0v9.1+30 more2013-01-10
CVE-2013-0611 [CRITICAL] CVE-2013-0611: Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attacker Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code via unspecified vectors, related to a "logic error," a different vulnerability than CVE-2013-0607, CVE-2013-0608, CVE-2013-0614, and CVE-2013-0618.
nvd
CVE-2021-28553P3HIGHCVSS 8.8≥ 17.011.30059, ≤ 17.011.30194≥ 20.001.30005, ≤ 20.001.30020+1 more2021-09-02
CVE-2021-28553 [HIGH] CWE-416 CVE-2021-28553: Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2 Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user i
nvd
CVE-2021-28564P3HIGHCVSS 8.8≥ 17.011.30059, ≤ 17.011.30194≥ 20.001.30005, ≤ 20.001.30020+1 more2021-09-02
CVE-2021-28564 [HIGH] CWE-787 CVE-2021-28564: Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2 Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Out-of-bounds Write vulnerability within the ImageTool component. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploi
nvd
CVE-2017-11223P3HIGHCVSS 8.8≥ 17.011.00000, ≤ 17.011.300662017-08-11
CVE-2017-11223 [HIGH] CWE-416 CVE-2017-11223: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in the core of the XFA engine. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2013-0607P3CRITICALCVSS 10.0v9.0v9.1+30 more2013-01-10
CVE-2013-0607 [CRITICAL] CWE-94 CVE-2013-0607: Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attacker Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code via unspecified vectors, related to a "logic error," a different vulnerability than CVE-2013-0608, CVE-2013-0611, CVE-2013-0614, and CVE-2013-0618.
nvd
CVE-2013-0614P3CRITICALCVSS 10.0v9.0v9.1+30 more2013-01-10
CVE-2013-0614 [CRITICAL] CVE-2013-0614: Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attacker Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code via unspecified vectors, related to a "logic error," a different vulnerability than CVE-2013-0607, CVE-2013-0608, CVE-2013-0611, and CVE-2013-0618.
nvd
CVE-2015-5098P3CRITICALCVSS 10.0≥ 10.0, ≤ 10.1.14≥ 11.0.0, ≤ 11.0.112015-07-15
CVE-2015-5098 [CRITICAL] CVE-2015-5098: Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5096
nvd
CVE-2015-5096P3CRITICALCVSS 10.0≥ 10.0, ≤ 10.1.14≥ 11.0.0, ≤ 11.0.112015-07-15
CVE-2015-5096 [CRITICAL] CWE-787 CVE-2015-5096: Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2
nvd
CVE-2015-5105P3CRITICALCVSS 10.0≥ 10.0, ≤ 10.1.14≥ 11.0.0, ≤ 11.0.112015-07-15
CVE-2015-5105 [CRITICAL] CVE-2015-5105: Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5096
nvd