Adobe Reader vulnerabilities
359 known vulnerabilities affecting adobe/reader.
Total CVEs
359
CISA KEV
0
Public exploits
9
Exploited in wild
2
Severity breakdown
CRITICAL198HIGH123MEDIUM31LOW7
Vulnerabilities
Page 6 of 18
CVE-2017-3121P3HIGHCVSS 8.8≥ 11.0.0, < 11.0.212017-08-11
CVE-2017-3121 [HIGH] CWE-119 CVE-2017-3121: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the Enhanced Metafile Format (EMF) parser. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3016P3HIGHCVSS 8.8≥ 11.0.0, < 11.0.212017-08-11
CVE-2017-3016 [HIGH] CWE-119 CVE-2017-3016: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3116P3HIGHCVSS 8.8≥ 11.0.0, < 11.0.212017-08-11
CVE-2017-3116 [HIGH] CWE-119 CVE-2017-3116: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the MakeAccessible plugin when parsing TrueType font data. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11254P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11254 [HIGH] CWE-416 CVE-2017-11254: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in the Acrobat/Reader's JavaScript engine. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11235P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11235 [HIGH] CWE-416 CVE-2017-11235: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in the image conversion engine when decompressing JPEG data. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11231P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11231 [HIGH] CWE-416 CVE-2017-11231: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in Acrobat/Reader rendering engine. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11228P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11228 [HIGH] CWE-119 CVE-2017-11228: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing JPEG 2000 (JP2) code stream data. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11227P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11227 [HIGH] CWE-119 CVE-2017-11227: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11270P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11270 [HIGH] CWE-119 CVE-2017-11270: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data representing icons. Successful exploitation could lead to arbitrary code execution
nvd
CVE-2017-11222P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11222 [HIGH] CWE-119 CVE-2017-11222: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the Product Representation Compact (PRC) engine. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11268P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11268 [HIGH] CWE-119 CVE-2017-11268: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private JPEG data. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-4095P3CRITICALCVSS 9.8≤ 11.0.172016-11-10
CVE-2016-4095 [CRITICAL] CWE-119 CVE-2016-4095: Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243,
Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2016-1038P3CRITICALCVSS 10.0≤ 11.0.152016-05-11
CVE-2016-1038 [CRITICAL] CWE-284 CVE-2016-1038: Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172,
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2016-1039, CVE-2016-1040, CVE-2016-1041, CV
nvd
CVE-2016-1044P3CRITICALCVSS 10.0≤ 11.0.152016-05-11
CVE-2016-1044 [CRITICAL] CVE-2016-1044: Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172,
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2016-1038, CVE-2016-1039, CVE-2016-1040, CVE-2016-1
nvd
CVE-2010-1278P3CRITICALCVSS 9.3v8.0.0v8.1.1+11 more2010-04-22
CVE-2010-1278 [CRITICAL] CWE-119 CVE-2010-1278: Buffer overflow in the Atlcom.get_atlcom ActiveX control in gp.ocx in Adobe Download Manager, as use
Buffer overflow in the Atlcom.get_atlcom ActiveX control in gp.ocx in Adobe Download Manager, as used in Adobe Reader and Acrobat 8.x before 8.2 and 9.x before 9.3, allows remote attackers to execute arbitrary code via unspecified parameters.
nvd
CVE-2017-3037P3CRITICALCVSS 9.8≤ 11.0.192017-04-12
CVE-2017-3037 [CRITICAL] CWE-119 CVE-2017-3037: Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlie
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the JavaScript engine. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3010P3CRITICALCVSS 9.8≥ 11.0.0, ≤ 11.0.182017-03-31
CVE-2017-3010 [CRITICAL] CWE-119 CVE-2017-3010: Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlie
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the rendering engine. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11251P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11251 [HIGH] CWE-119 CVE-2017-11251: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the JPEG 2000 parsing module. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3119P3HIGHCVSS 8.8≥ 11.0.0, < 11.0.212017-08-11
CVE-2017-3119 [HIGH] CWE-119 CVE-2017-3119: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in Acrobat/Reader 11.0.19 engine. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-11237P3HIGHCVSS 8.8≥ 11.0.0, ≤ 11.0.202017-08-11
CVE-2017-11237 [HIGH] CWE-119 CVE-2017-11237: Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earl
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the font parsing module. Successful exploitation could lead to arbitrary code execution.
nvd