Adobe Acrobat Reader Dc vulnerabilities
1,798 known vulnerabilities affecting adobe/acrobat_reader_dc.
Total CVEs
1,798
CISA KEV
7
actively exploited
Public exploits
30
Exploited in wild
15
Severity breakdown
CRITICAL449HIGH859MEDIUM456LOW34
Vulnerabilities
Page 88 of 90
CVE-2020-9696P4MEDIUMCVSS 5.5≥ 15.006.30060, ≤ 15.006.30523≥ 15.008.20082, ≤ 20.009.20074+2 more2020-08-19
CVE-2020-9696 [MEDIUM] CVE-2020-9696: Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and ear
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a security bypass vulnerability. Successful exploitation could lead to security feature bypass.
nvd
CVE-2020-9608P4MEDIUMCVSS 5.5≥ 15.006.30060, < 15.006.30518≥ 15.008.20082, < 20.006.20042+1 more2020-06-25
CVE-2020-9608 [MEDIUM] CWE-125 CVE-2020-9608: Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.3
Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2021-39857P4MEDIUMCVSS 4.3≥ 15.008.20082, ≤ 21.005.20058≥ 15.008.20082, ≤ 21.005.200602021-09-29
CVE-2021-39857 [MEDIUM] CWE-200 CVE-2021-39857: Adobe Acrobat Reader DC add-on for Internet Explorer versions 2021.005.20060 (and earlier), 2020.004
Adobe Acrobat Reader DC add-on for Internet Explorer versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to check for existence of local files. Exploitation of this issue requires use
nvd
CVE-2021-44702P4MEDIUMCVSS 4.3≥ 21.001.20149, ≤ 21.007.200992022-01-14
CVE-2021-44702 [MEDIUM] CWE-200 CVE-2021-44702: Acrobat Reader DC ActiveX Control versions 21.007.20099 (and earlier), 20.004.30017 (and earlier) an
Acrobat Reader DC ActiveX Control versions 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obtain NTLMv2 credentials. Exploitation of this issue requires user interaction in that a victim mus
nvd
CVE-2020-9702P4MEDIUMCVSS 5.5≥ 15.006.30060, ≤ 15.006.30523≥ 15.008.20082, ≤ 20.009.20074+2 more2020-08-19
CVE-2020-9702 [MEDIUM] CWE-400 CVE-2020-9702: Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and ear
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a stack exhaustion vulnerability. Successful exploitation could lead to application denial-of-service.
nvd
CVE-2020-9703P4MEDIUMCVSS 5.5≥ 15.006.30060, ≤ 15.006.30523≥ 15.008.20082, ≤ 20.009.20074+2 more2020-08-19
CVE-2020-9703 [MEDIUM] CWE-400 CVE-2020-9703: Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and ear
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a stack exhaustion vulnerability. Successful exploitation could lead to application denial-of-service.
nvd
CVE-2020-9610P4MEDIUMCVSS 5.5≥ 15.006.30060, < 15.006.30518≥ 15.008.20082, < 20.006.20042+1 more2020-06-25
CVE-2020-9610 [MEDIUM] CWE-476 CVE-2020-9610: Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.3
Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a null pointer vulnerability. Successful exploitation could lead to application denial-of-service.
nvd
CVE-2020-9611P4MEDIUMCVSS 5.5≥ 15.006.30060, < 15.006.30518≥ 15.008.20082, < 20.006.20042+1 more2020-06-25
CVE-2020-9611 [MEDIUM] CWE-400 CVE-2020-9611: Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.3
Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a stack exhaustion vulnerability. Successful exploitation could lead to application denial-of-service.
nvd
CVE-2026-47925P4MEDIUMCVSS 5.5≥ 15.008.20082, < 26.001.216622026-06-09
CVE-2026-47925 [MEDIUM] CWE-190 CVE-2026-47925: Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Integer Overflow o
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in
nvd
CVE-2021-21060P4MEDIUMCVSS 4.6≤ 20.013.200742021-02-11
CVE-2021-21060 [MEDIUM] CWE-20 CVE-2021-21060: Adobe Acrobat Pro DC versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.01
Adobe Acrobat Pro DC versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an improper input validation vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requires us
nvd
CVE-2022-28252P4LOWCVSS 3.3≥ 15.008.20082, ≤ 22.001.200852022-05-11
CVE-2022-28252 [LOW] CWE-125 CVE-2022-28252: Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (a
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exp
nvd
CVE-2024-49531P4MEDIUMCVSS 5.5≥ 15.007.20033, < 24.005.203202024-12-10
CVE-2024-49531 [MEDIUM] CWE-476 CVE-2024-49531: Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and ear
Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this
nvd
CVE-2025-47111P4MEDIUMCVSS 5.5fixed in 25.001.20531fixed in 25.001.205292025-06-10
CVE-2025-47111 [MEDIUM] CWE-476 CVE-2025-47111: Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a NULL
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing a disruption in service. Exploitation of this issue requires user interaction in that a v
nvd
CVE-2017-3022P4LOWCVSS 3.3≤ 15.006.30280≤ 15.023.200702017-04-12
CVE-2017-3022 [LOW] CWE-125 CVE-2017-3022: Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlie
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability when parsing the header of a JPEG 2000 file.
nvd
CVE-2022-28269P4LOWCVSS 3.3≥ 15.008.20082, ≤ 22.001.200852022-05-11
CVE-2022-28269 [LOW] CWE-416 CVE-2022-28269: Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of Annotation objects that could result in a memory leak in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a m
nvd
CVE-2020-24431P4MEDIUMCVSS 4.4≤ 17.011.30175≤ 20.012.200482020-11-05
CVE-2020-24431 [MEDIUM] CWE-285 CVE-2020-24431: Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) for macOS are affected by a security feature bypass that could result in dynamic library code injection by the Adobe Reader process. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2021-39844P4LOWCVSS 3.3≥ 15.008.20082, ≤ 21.005.20058≥ 15.008.20082, ≤ 21.005.200602021-09-29
CVE-2021-39844 [LOW] CWE-125 CVE-2021-39844: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal
nvd
CVE-2021-35986P4LOWCVSS 3.3≥ 15.008.20082, ≤ 21.005.20054≥ 17.011.30059, ≤ 17.011.30197+1 more2021-08-20
CVE-2021-35986 [LOW] CWE-843 CVE-2021-35986: Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.3
Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Type Confusion vulnerability. An unauthenticated attacker could leverage this vulnerability to read arbitrary system information in the context of the current user. Exploitation of this issue requires user interactio
nvd
CVE-2019-8035P4MEDIUMCVSS 4.3≥ 15.006.30060, < 15.006.30499≥ 15.008.20082, < 19.012.20036+1 more2019-08-20
CVE-2019-8035 [MEDIUM] CWE-125 CVE-2019-8035: Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.3
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .
nvd
CVE-2019-8052P4MEDIUMCVSS 4.3≥ 15.006.30060, < 15.006.30499≥ 15.008.20082, < 19.012.20036+1 more2019-08-20
CVE-2019-8052 [MEDIUM] CWE-125 CVE-2019-8052: Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.3
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .
nvd