cbcvebase.

Adobe Reader vulnerabilities

359 known vulnerabilities affecting adobe/reader.

Total CVEs
359
CISA KEV
0
Public exploits
9
Exploited in wild
2
Severity breakdown
CRITICAL198HIGH123MEDIUM31LOW7

Vulnerabilities

Page 16 of 18
CVE-2017-11255P3MEDIUMCVSS 6.5≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11255 [MEDIUM] CWE-119 CVE-2017-11255: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing TIFF color map data. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11258P3MEDIUMCVSS 6.5≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11258 [MEDIUM] CWE-119 CVE-2017-11258: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data and the embedded GIF image. Successful exploitation could lead to arbitrary code
nvd
CVE-2017-11239P3MEDIUMCVSS 6.5≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11239 [MEDIUM] CWE-119 CVE-2017-11239: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to text strings. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11238P3MEDIUMCVSS 6.5≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11238 [MEDIUM] CWE-119 CVE-2017-11238: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to curve drawing. Successful exploitation could lead to arbitrary code execution
nvd
CVE-2017-3017P3HIGHCVSS 7.8≤ 11.0.192017-04-12
CVE-2017-3017 [HIGH] CWE-119 CVE-2017-3017: Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlie Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability when handling a malformed PDF file. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-2950P3HIGHCVSS 7.8≤ 11.0.182017-01-11
CVE-2017-2950 [HIGH] CWE-416 CVE-2017-2950: Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlie Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerability in the XFA engine, related to layout functionality. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3122P3MEDIUMCVSS 6.5≥ 11.0.0, < 11.0.212017-08-11
CVE-2017-3122 [MEDIUM] CWE-119 CVE-2017-3122: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to Bezier curves. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3027P3HIGHCVSS 7.8≤ 11.0.192017-04-12
CVE-2017-3027 [HIGH] CWE-416 CVE-2017-3027: Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlie Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable use after free vulnerability in the XFA module, related to the choiceList element. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-2961P3HIGHCVSS 7.8≤ 11.0.182017-01-11
CVE-2017-2961 [HIGH] CWE-416 CVE-2017-2961: Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlie Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerability in the XFA engine, related to validation functionality. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-2951P3HIGHCVSS 7.8≤ 11.0.182017-01-11
CVE-2017-2951 [HIGH] CWE-416 CVE-2017-2951: Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlie Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerability in the XFA engine, related to sub-form functionality. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-2956P3HIGHCVSS 7.8≤ 11.0.182017-01-11
CVE-2017-2956 [HIGH] CWE-416 CVE-2017-2956: Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlie Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerability in the JavaScript engine, related to manipulation of the navigation pane. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3030P3HIGHCVSS 7.8≤ 11.0.192017-04-12
CVE-2017-3030 [HIGH] CWE-119 CVE-2017-3030: Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlie Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the AES module. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3019P3HIGHCVSS 7.8≤ 11.0.192017-04-12
CVE-2017-3019 [HIGH] CWE-125 CVE-2017-3019: Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlie Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the Product Representation Compact (PRC) format parser. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3039P3HIGHCVSS 7.8≤ 11.0.192017-04-12
CVE-2017-3039 [HIGH] CWE-119 CVE-2017-3039: Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlie Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the PPKLite security handler. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3040P3HIGHCVSS 7.8≤ 11.0.192017-04-12
CVE-2017-3040 [HIGH] CWE-119 CVE-2017-3040: Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlie Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the JBIG2 image compression module. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3065P3HIGHCVSS 7.8≤ 11.0.192017-04-12
CVE-2017-3065 [HIGH] CWE-119 CVE-2017-3065: Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlie Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the font manipulation functionality. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3041P3HIGHCVSS 7.8≤ 11.0.192017-04-12
CVE-2017-3041 [HIGH] CWE-119 CVE-2017-3041: Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlie Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability when parsing font data in the MakeAccessible plugin. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3056P3HIGHCVSS 7.8≤ 11.0.192017-04-12
CVE-2017-3056 [HIGH] CWE-119 CVE-2017-3056: Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlie Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the JavaScript engine, related to string manipulation. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-2964P3HIGHCVSS 7.8≤ 11.0.182017-01-11
CVE-2017-2964 [HIGH] CWE-119 CVE-2017-2964: Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlie Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion engine, related to the parsing of JPEG EXIF metadata. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-2941P3HIGHCVSS 7.8≤ 11.0.182017-01-11
CVE-2017-2941 [HIGH] CWE-119 CVE-2017-2941: Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlie Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability when processing Compact Font Format data. Successful exploitation could lead to arbitrary code execution.
nvd