VendorsAdobeacrobatany version
Vulnerabilities

Adobe Acrobat any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1120CVEs
CVE-2026-47952
Acrobat Reader | Heap-based Buffer Overflow (CWE-122)
Published 2026-06-09 · Analyzed
7.8EPSS 0.003
CVE-2025-27161
Acrobat Reader | Out-of-bounds Read (CWE-125)
Published 2025-03-11 · Analyzed
7.8EPSS 0.003
CVE-2025-27162
Acrobat Reader | Access of Uninitialized Pointer (CWE-824)
Published 2025-03-11 · Analyzed
7.8EPSS 0.003
CVE-2024-34122
T5 Acrobat Vulnerability - Exploitable crash in DecodeTile
Published 2024-07-02 · Modified
7.8EPSS 0.003
CVE-2026-81987
Acrobat Reader | Integer Overflow or Wraparound (CWE-190)
Published 2026-09-08 · Analyzed
7.8EPSS 0.003
CVE-2022-44512
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2024-12-18 · Analyzed
7.8EPSS 0.003
CVE-2022-44513
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2024-12-18 · Analyzed
7.8EPSS 0.003
CVE-2026-80161
Acrobat Reader | Access of Resource Using Incompatible Type ('Type Confusion') (CWE-843)
Published 2026-09-08 · Analyzed
7.8EPSS 0.003
CVE-2026-79907
Acrobat Reader | Double Free (CWE-415)
Published 2026-09-08 · Analyzed
7.8EPSS 0.003
CVE-2026-81983
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2026-09-08 · Analyzed
7.8EPSS 0.003
CVE-2026-81981
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2026-09-08 · Analyzed
7.8EPSS 0.003
CVE-2026-81980
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2026-09-08 · Analyzed
7.8EPSS 0.003
CVE-2026-81979
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2026-09-08 · Analyzed
7.8EPSS 0.003
CVE-2026-79908
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2026-09-08 · Analyzed
7.8EPSS 0.003
CVE-2026-47965
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2026-06-12 · Analyzed
7.8EPSS 0.003
CVE-2026-47911
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2026-06-09 · Analyzed
7.8EPSS 0.003
CVE-2020-24428
Acrobat Reader DC for macOS Race Condition Vulnerability Could Lead to Privilege Escalation
Published 2020-11-05 · Modified
7.7EPSS 0.023
CVE-2026-47937
Acrobat Reader | Uncontrolled Search Path Element (CWE-427)
Published 2026-06-09 · Analyzed
7.7EPSS 0.003
CVE-2016-1079
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to obtain sensitive information from process memory via unspecified vectors, a different vulnerability than CVE-2016-1092.
Published 2016-05-11 · Modified
7.5EPSS 0.100
CVE-2008-4815
Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.2 and earlier on Unix and Linux allows attackers to gain privileges via a Trojan Horse program in an unspecified directory that is associated with an insecure RPATH.
Published 2008-11-05 · Modified
7.5EPSS 0.078
CVE-2015-6713
The Function call implementation in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-6707, CVE-2015-6708, CVE-2015-6709, CVE-2015-6710, CVE-2015-6711, CVE-2015-6712, CVE-2015-6714, CVE-2015-6715, CVE-2015-6716, CVE-2015-6717, CVE-2015-6718, CVE-2015-6719, CVE-2015-6720, CVE-2015-6721, CVE-2015-6722, CVE-2015-6723, CVE-2015-6724, CVE-2015-6725, CVE-2015-7614, CVE-2015-7616, CVE-2015-7618, CVE-2015-7619, CVE-2015-7620, and CVE-2015-7623.
Published 2015-10-14 · Modified
7.5EPSS 0.076
CVE-2011-4371
Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
Published 2012-01-10 · Modified
7.5EPSS 0.062
CVE-2011-4370
Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-4372 and CVE-2011-4373.
Published 2012-01-10 · Modified
7.5EPSS 0.062
CVE-2017-16366
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a security bypass vulnerability in the AcroPDF plugin.
Published 2017-12-09 · Modified
7.5EPSS 0.059
CVE-2015-4446
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and perform a transition from Low Integrity to Medium Integrity via unspecified vectors, a different vulnerability than CVE-2015-5090 and CVE-2015-5106.
Published 2015-07-15 · Modified
7.5EPSS 0.051
CVE-2017-3009
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable buffer overflow vulnerability in the JPEG2000 parser. Successful exploitation could lead to information disclosure.
Published 2017-03-31 · Modified
7.5EPSS 0.044
CVE-2016-1092
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to obtain sensitive information from process memory via unspecified vectors, a different vulnerability than CVE-2016-1079.
Published 2016-05-11 · Modified
7.5EPSS 0.041
CVE-2026-48294
Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. An attacker could exploit this vulnerability to gain access to data regarding the victim's session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Published 2026-06-16 · Analyzed
7.4EPSS 0.012
CVE-2022-28247
Adobe Acrobat Uninstaller Hard Link Leads To Remote Code Execution
Published 2022-05-11 · Modified
7.3EPSS 0.005
CVE-2015-5090
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and perform a transition from Low Integrity to Medium Integrity via unspecified vectors, a different vulnerability than CVE-2015-4446 and CVE-2015-5106.
Published 2015-07-15 · Modified
7.2EPSS 0.011
CVE-2020-29075
PDF Injection BlackHat Talk
Published 2021-02-23 · Modified
7.1EPSS 0.079
CVE-2024-39420
Acrobat Reader | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)
Published 2024-08-14 · Modified
7.0EPSS 0.035
CVE-2024-39425
Security vulnerability in AdobeARMHelper
Published 2024-08-14 · Analyzed
7.0EPSS 0.002
CVE-2015-8458
Heap-based buffer overflow in AGM.dll in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to execute arbitrary code via a multiple-layer PDF document, a different vulnerability than CVE-2015-6696 and CVE-2015-6698.
Published 2015-12-21 · Modified
6.8EPSS 0.083
CVE-2015-5110
Stack-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors.
Published 2015-07-15 · Modified
6.8EPSS 0.082
CVE-2015-6696
Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-6698.
Published 2015-10-14 · Modified
6.8EPSS 0.078
CVE-2015-6698
Heap-based buffer overflow in the AcroForm implementation in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-6696.
Published 2015-10-14 · Modified
6.8EPSS 0.078
CVE-2012-0777
The JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 on Mac OS X and Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Published 2012-04-10 · Modified
6.8EPSS 0.071
CVE-2015-7614
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions and execute arbitrary commands via an app.launchURL call, a different vulnerability than CVE-2015-6707, CVE-2015-6708, CVE-2015-6709, CVE-2015-6710, CVE-2015-6711, CVE-2015-6712, CVE-2015-6713, CVE-2015-6714, CVE-2015-6715, CVE-2015-6716, CVE-2015-6717, CVE-2015-6718, CVE-2015-6719, CVE-2015-6720, CVE-2015-6721, CVE-2015-6722, CVE-2015-6723, CVE-2015-6724, CVE-2015-6725, CVE-2015-7616, CVE-2015-7618, CVE-2015-7619, CVE-2015-7620, and CVE-2015-7623.
Published 2015-10-14 · Modified
6.8EPSS 0.070
CVE-2015-7619
The ANShareFile2 method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-6707, CVE-2015-6708, CVE-2015-6709, CVE-2015-6710, CVE-2015-6711, CVE-2015-6712, CVE-2015-6713, CVE-2015-6714, CVE-2015-6715, CVE-2015-6716, CVE-2015-6717, CVE-2015-6718, CVE-2015-6719, CVE-2015-6720, CVE-2015-6721, CVE-2015-6722, CVE-2015-6723, CVE-2015-6724, CVE-2015-6725, CVE-2015-7614, CVE-2015-7616, CVE-2015-7618, CVE-2015-7620, and CVE-2015-7623.
Published 2015-10-14 · Modified
6.8EPSS 0.065
← Prev20 / 28Next →