cbcvebase.

Adobe Reader vulnerabilities

359 known vulnerabilities affecting adobe/reader.

Total CVEs
359
CISA KEV
0
Public exploits
9
Exploited in wild
2
Severity breakdown
CRITICAL198HIGH123MEDIUM31LOW7

Vulnerabilities

Page 5 of 18
CVE-2017-2960P3HIGHCVSS 7.8≤ 11.0.182017-01-11
CVE-2017-2960 [HIGH] CWE-119 CVE-2017-2960: Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlie Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion engine, related to parsing of EXIF metadata. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11218P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11218 [HIGH] CWE-416 CVE-2017-11218: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in XFA event management. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3113P3HIGHCVSS 8.8≥ 11.0.0, < 11.0.212017-08-11
CVE-2017-3113 [HIGH] CWE-416 CVE-2017-3113: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in JavaScript engine when creating large strings. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2011-4372P3CRITICALCVSS 9.8≤ 10.1.1≤ 9.4.6+3 more2012-01-10
CVE-2011-4372 [CRITICAL] CVE-2011-4372: Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-4370 and CVE-2011-4373.
nvd
CVE-2017-11212P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11212 [HIGH] CWE-119 CVE-2017-11212: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to text output. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11216P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11216 [HIGH] CWE-119 CVE-2017-11216: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to bitmap transformations. Successful exploitation could lead to arbitrary code ex
nvd
CVE-2017-11256P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11256 [HIGH] CWE-416 CVE-2017-11256: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability when generating content using XFA layout engine. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11260P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11260 [HIGH] CWE-119 CVE-2017-11260: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data interpreted as a GIF image. Successful exploitation could lead to arbitrary code e
nvd
CVE-2017-11271P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11271 [HIGH] CWE-119 CVE-2017-11271: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to transfer of pixel blocks. Successful exploitation could lead to arbitrary code
nvd
CVE-2017-11261P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11261 [HIGH] CWE-119 CVE-2017-11261: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data and the embedded TIF image. Successful exploitation could lead to arbitrary code e
nvd
CVE-2017-11269P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11269 [HIGH] CWE-119 CVE-2017-11269: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) image stream data. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11262P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11262 [HIGH] CWE-119 CVE-2017-11262: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to drawing ASCII text string. Successful exploitation could lead to arbitrary code
nvd
CVE-2017-11214P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11214 [HIGH] CWE-119 CVE-2017-11214: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to rendering a path. Successful exploitation could lead to arbitrary code executio
nvd
CVE-2017-11267P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11267 [HIGH] CWE-119 CVE-2017-11267: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data interpreted as JPEG data. Successful exploitation could lead to arbitrary code exe
nvd
CVE-2017-11226P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11226 [HIGH] CWE-119 CVE-2017-11226: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image processing engine when processing JPEG 2000 (JP2) code stream data. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3124P3CRITICALCVSS 9.8≥ 11.0.0, < 11.0.212017-08-11
CVE-2017-3124 [CRITICAL] CWE-119 CVE-2017-3124: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the picture exchange (PCX) file format parsing module. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11224P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11224 [HIGH] CWE-416 CVE-2017-11224: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in the XFA layout engine. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11219P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11219 [HIGH] CWE-416 CVE-2017-11219: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in the XFA rendering engine. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11221P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11221 [HIGH] CWE-704 CVE-2017-11221: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable type confusion vulnerability in the annotation functionality. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11257P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11257 [HIGH] CWE-704 CVE-2017-11257: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable type confusion vulnerability in the XFA layout engine. Successful exploitation could lead to arbitrary code execution.
nvd
Adobe Reader vulnerabilities | cvebase