Adobe Acrobat Reader Dc vulnerabilities
1,779 known vulnerabilities affecting adobe/acrobat_reader_dc.
Total CVEs
1,779
CISA KEV
7
actively exploited
Public exploits
26
Exploited in wild
5
Severity breakdown
CRITICAL449HIGH847MEDIUM451LOW32
Vulnerabilities
Page 16 of 89
CVE-2021-44703HIGHCVSS 7.8≥ 15.008.20082, ≤ 21.007.200992022-01-14
CVE-2021-44703 [HIGH] CWE-121 CVE-2021-44703: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a stack buffer overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in t
nvd
CVE-2021-44711HIGHCVSS 7.8≥ 15.008.20082, ≤ 21.007.200992022-01-14
CVE-2021-44711 [HIGH] CWE-190 CVE-2021-44711: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious fil
nvd
CVE-2021-44741MEDIUMCVSS 5.5≥ 15.008.20082, ≤ 21.007.200992022-01-14
CVE-2021-44741 [MEDIUM] CWE-476 CVE-2021-44741: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. E
nvd
CVE-2021-44742MEDIUMCVSS 5.5≥ 15.008.20082, ≤ 21.007.200992022-01-14
CVE-2021-44742 [MEDIUM] CWE-125 CVE-2021-44742: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of th
nvd
CVE-2021-44739MEDIUMCVSS 4.3≥ 21.001.20149, ≤ 21.007.200992022-01-14
CVE-2021-44739 [MEDIUM] CWE-200 CVE-2021-44739: Acrobat Reader DC ActiveX Control versions 21.007.20099 (and earlier), 20.004.30017 (and earlier) an
Acrobat Reader DC ActiveX Control versions 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obtain NTLMv2 credentials. Exploitation of this issue requires user interaction in that a victim mus
nvd
CVE-2021-45067MEDIUMCVSS 5.5≥ 15.008.20082, ≤ 21.007.200992022-01-14
CVE-2021-45067 [MEDIUM] CWE-788 CVE-2021-45067: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an Access of Memory Location After End of Buffer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue
nvd
CVE-2021-44702MEDIUMCVSS 4.3≥ 21.001.20149, ≤ 21.007.200992022-01-14
CVE-2021-44702 [MEDIUM] CWE-200 CVE-2021-44702: Acrobat Reader DC ActiveX Control versions 21.007.20099 (and earlier), 20.004.30017 (and earlier) an
Acrobat Reader DC ActiveX Control versions 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obtain NTLMv2 credentials. Exploitation of this issue requires user interaction in that a victim mus
nvd
CVE-2021-44713MEDIUMCVSS 5.5≥ 15.008.20082, ≤ 21.007.200992022-01-14
CVE-2021-44713 [MEDIUM] CWE-416 CVE-2021-44713: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in application denial of service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2021-45063MEDIUMCVSS 5.5≥ 15.008.20082, ≤ 21.007.200992022-01-14
CVE-2021-45063 [MEDIUM] CWE-416 CVE-2021-45063: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of t
nvd
CVE-2021-44712MEDIUMCVSS 5.5≥ 15.008.20082, ≤ 21.007.200992022-01-14
CVE-2021-44712 [MEDIUM] CWE-788 CVE-2021-44712: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an Access of Memory Location After End of Buffer vulnerability that could lead to application denial-of-service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2021-44715MEDIUMCVSS 5.5≥ 15.008.20082, ≤ 21.007.200992022-01-14
CVE-2021-44715 [MEDIUM] CWE-125 CVE-2021-44715: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR.
nvd
CVE-2021-44740MEDIUMCVSS 5.5≥ 15.008.20082, ≤ 21.007.200992022-01-14
CVE-2021-44740 [MEDIUM] CWE-476 CVE-2021-44740: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. E
nvd
CVE-2021-44714LOWCVSS 3.3≥ 15.008.20082, ≤ 21.007.200992022-01-14
CVE-2021-44714 [LOW] CWE-657 CVE-2021-44714: Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (a
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a Violation of Secure Design Principles that could lead to a Security feature bypass. Acrobat Reader DC displays a warning message when a user clicks on a PDF file, which could be used by an attacker to mislead the user. In af
nvd
CVE-2021-40728HIGHCVSS 7.8≥ 15.008.20082, ≤ 21.007.20095≥ 15.008.20082, ≤ 21.007.200962021-10-15
CVE-2021-40728 [HIGH] CWE-416 CVE-2021-40728: Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015
Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 (and earlier), and 17.011.30202 (and earlier) is affected by a use-after-free vulnerability in the processing of the GetURL function on a global object window that could result in arbitrary code execution in the context of the current user. Exploitatio
nvd
CVE-2021-40731HIGHCVSS 7.8≥ 15.008.20082, ≤ 21.007.20095≥ 15.008.20082, ≤ 21.007.200962021-10-15
CVE-2021-40731 [HIGH] CWE-787 CVE-2021-40731: Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015
Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 (and earlier), and 17.011.30202 (and earlier) is affected by an out-of-bounds write vulnerability when parsing a crafted JPEG2000 file, which could result in arbitrary code execution in the context of the current user. Exploitation of this issue requir
nvd
CVE-2021-40730LOWCVSS 3.3≥ 15.008.20082, ≤ 21.007.20095≥ 15.008.20082, ≤ 21.007.200962021-10-15
CVE-2021-40730 [LOW] CWE-416 CVE-2021-40730: Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015
Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 (and earlier), and 17.011.30202 (and earlier) is affected by a use-after-free that allow a remote attacker to disclose sensitive information on affected installations of of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerabil
nvd
CVE-2021-40729LOWCVSS 3.3≥ 15.008.20082, ≤ 21.007.20095≥ 15.008.20082, ≤ 21.007.200962021-10-15
CVE-2021-40729 [LOW] CWE-125 CVE-2021-40729: Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015
Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 (and earlier), and 17.011.30202 (and earlier) is affected by a out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this iss
nvd
CVE-2021-40726HIGHCVSS 7.8≥ 17.011.30059, ≤ 17.011.30199≥ 20.001.30005, ≤ 20.004.30006+2 more2021-10-07
CVE-2021-40726 [HIGH] CWE-416 CVE-2021-40726: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability when processing AcroForm field that could result in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability in that the tar
nvd
CVE-2021-40725HIGHCVSS 7.8≥ 17.011.30059, ≤ 17.011.30199≥ 20.001.30005, ≤ 20.004.30006+2 more2021-10-07
CVE-2021-40725 [HIGH] CWE-416 CVE-2021-40725: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability when processing AcroForm listbox that could result in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability in that the t
nvd
CVE-2021-21089LOWCVSS 3.3≥ 20.006.20034, ≤ 20.013.20074≥ 20.001.30005, ≤ 20.001.30018+1 more2021-09-30
CVE-2021-21089 [LOW] CWE-125 CVE-2021-21089: Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to locally escalate privileges in the context of the current user. Exploitation of this issue requires user int
nvd