VendorsAdobeacrobatall versions
Vulnerabilities

Adobe Acrobat

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1414CVEs
CVE-2017-11229
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has a security bypass vulnerability when manipulating Forms Data Format (FDF).
Published 2017-08-11 · Modified
8.8EPSS 0.067
CVE-2017-3119
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in Acrobat/Reader 11.0.19 engine. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
8.8EPSS 0.066
CVE-2016-0931
Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted FileAttachment annotation, a different vulnerability than CVE-2016-0933, CVE-2016-0936, CVE-2016-0938, CVE-2016-0939, CVE-2016-0942, CVE-2016-0944, CVE-2016-0945, and CVE-2016-0946.
Published 2016-01-14 · Modified
8.8EPSS 0.055
CVE-2016-1111
Double free vulnerability in Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allows attackers to execute arbitrary code via a crafted Graphics State dictionary.
Published 2016-04-30 · Modified
8.8EPSS 0.054
CVE-2016-4255
Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors.
Published 2016-07-13 · Modified
8.8EPSS 0.053
CVE-2016-4196
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4191, CVE-2016-4192, CVE-2016-4193, CVE-2016-4194, CVE-2016-4195, CVE-2016-4197, CVE-2016-4198, CVE-2016-4199, CVE-2016-4200, CVE-2016-4201, CVE-2016-4202, CVE-2016-4203, CVE-2016-4204, CVE-2016-4205, CVE-2016-4206, CVE-2016-4207, CVE-2016-4208, CVE-2016-4211, CVE-2016-4212, CVE-2016-4213, CVE-2016-4214, CVE-2016-4250, CVE-2016-4251, CVE-2016-4252, and CVE-2016-4254.
Published 2016-07-13 · Modified
8.8EPSS 0.045
CVE-2016-4197
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4191, CVE-2016-4192, CVE-2016-4193, CVE-2016-4194, CVE-2016-4195, CVE-2016-4196, CVE-2016-4198, CVE-2016-4199, CVE-2016-4200, CVE-2016-4201, CVE-2016-4202, CVE-2016-4203, CVE-2016-4204, CVE-2016-4205, CVE-2016-4206, CVE-2016-4207, CVE-2016-4208, CVE-2016-4211, CVE-2016-4212, CVE-2016-4213, CVE-2016-4214, CVE-2016-4250, CVE-2016-4251, CVE-2016-4252, and CVE-2016-4254.
Published 2016-07-13 · Modified
8.8EPSS 0.045
CVE-2016-4199
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4191, CVE-2016-4192, CVE-2016-4193, CVE-2016-4194, CVE-2016-4195, CVE-2016-4196, CVE-2016-4197, CVE-2016-4198, CVE-2016-4200, CVE-2016-4201, CVE-2016-4202, CVE-2016-4203, CVE-2016-4204, CVE-2016-4205, CVE-2016-4206, CVE-2016-4207, CVE-2016-4208, CVE-2016-4211, CVE-2016-4212, CVE-2016-4213, CVE-2016-4214, CVE-2016-4250, CVE-2016-4251, CVE-2016-4252, and CVE-2016-4254.
Published 2016-07-13 · Modified
8.8EPSS 0.045
CVE-2016-4200
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4191, CVE-2016-4192, CVE-2016-4193, CVE-2016-4194, CVE-2016-4195, CVE-2016-4196, CVE-2016-4197, CVE-2016-4198, CVE-2016-4199, CVE-2016-4201, CVE-2016-4202, CVE-2016-4203, CVE-2016-4204, CVE-2016-4205, CVE-2016-4206, CVE-2016-4207, CVE-2016-4208, CVE-2016-4211, CVE-2016-4212, CVE-2016-4213, CVE-2016-4214, CVE-2016-4250, CVE-2016-4251, CVE-2016-4252, and CVE-2016-4254.
Published 2016-07-13 · Modified
8.8EPSS 0.045
CVE-2016-4198
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4191, CVE-2016-4192, CVE-2016-4193, CVE-2016-4194, CVE-2016-4195, CVE-2016-4196, CVE-2016-4197, CVE-2016-4199, CVE-2016-4200, CVE-2016-4201, CVE-2016-4202, CVE-2016-4203, CVE-2016-4204, CVE-2016-4205, CVE-2016-4206, CVE-2016-4207, CVE-2016-4208, CVE-2016-4211, CVE-2016-4212, CVE-2016-4213, CVE-2016-4214, CVE-2016-4250, CVE-2016-4251, CVE-2016-4252, and CVE-2016-4254.
Published 2016-07-13 · Modified
8.8EPSS 0.045
CVE-2016-4202
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4191, CVE-2016-4192, CVE-2016-4193, CVE-2016-4194, CVE-2016-4195, CVE-2016-4196, CVE-2016-4197, CVE-2016-4198, CVE-2016-4199, CVE-2016-4200, CVE-2016-4201, CVE-2016-4203, CVE-2016-4204, CVE-2016-4205, CVE-2016-4206, CVE-2016-4207, CVE-2016-4208, CVE-2016-4211, CVE-2016-4212, CVE-2016-4213, CVE-2016-4214, CVE-2016-4250, CVE-2016-4251, CVE-2016-4252, and CVE-2016-4254.
Published 2016-07-13 · Modified
8.8EPSS 0.043
CVE-2016-4195
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4191, CVE-2016-4192, CVE-2016-4193, CVE-2016-4194, CVE-2016-4196, CVE-2016-4197, CVE-2016-4198, CVE-2016-4199, CVE-2016-4200, CVE-2016-4201, CVE-2016-4202, CVE-2016-4203, CVE-2016-4204, CVE-2016-4205, CVE-2016-4206, CVE-2016-4207, CVE-2016-4208, CVE-2016-4211, CVE-2016-4212, CVE-2016-4213, CVE-2016-4214, CVE-2016-4250, CVE-2016-4251, CVE-2016-4252, and CVE-2016-4254.
Published 2016-07-13 · Modified
8.8EPSS 0.043
CVE-2021-21021
Acrobat Reader DC Use-After-Free Vulnerability Could Lead To Arbitrary Code Execution
Published 2021-02-11 · Modified
8.8EPSS 0.041
CVE-2021-21028
Acrobat Reader DC Use-After-Free Vulnerability Could Lead To Arbitrary Code Execution
Published 2021-02-11 · Modified
8.8EPSS 0.041
CVE-2021-21033
Acrobat Reader DC Use-After-Free Vulnerability Could Lead To Arbitrary Code Execution
Published 2021-02-11 · Modified
8.8EPSS 0.041
CVE-2021-21035
Acrobat Reader DC Use-After-Free Vulnerability Could Lead To Arbitrary Code Execution
Published 2021-02-11 · Modified
8.8EPSS 0.041
CVE-2021-28553
Adobe Acrobat Reader use-after-free vulnerability could lead to arbitrary code execution
Published 2021-09-02 · Modified
8.8EPSS 0.035
CVE-2021-28564
Adobe Acrobat Reader out-of-bounds write vulnerability could lead to arbitrary code execution
Published 2021-09-02 · Modified
8.8EPSS 0.035
CVE-2021-28561
Adobe Acrobat Reader memory corruption vulnerability could lead to remote code execution
Published 2021-09-02 · Modified
8.8EPSS 0.033
CVE-2026-81996
Acrobat Reader | Incorrect Authorization (CWE-863)
Published 2026-09-08 · Analyzed
8.8EPSS 0.002
CVE-2026-34621
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
Published 2026-04-11 · Analyzed
8.6KEVEPSS 0.022
CVE-2026-34622
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
Published 2026-04-14 · Analyzed
8.6EPSS 0.007
CVE-2016-1008
Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.15, Acrobat and Acrobat Reader DC Classic before 15.006.30121, and Acrobat and Acrobat Reader DC Continuous before 15.010.20060 on Windows and OS X allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
Published 2016-03-09 · Modified
8.4EPSS 0.011
CVE-2026-81994
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
Published 2026-09-08 · Analyzed
8.2EPSS 0.006
CVE-2021-28545
Acrobat Reader DC Missing Support for Integrity Check
Published 2021-04-01 · Modified
8.1EPSS 0.023
CVE-2021-39843
Adobe Acrobat Reader XObject Out-of-Bound Write Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.767
CVE-2021-39836
Adobe Acrobat Reader DC AcroForm buttonGetIcon Use-After-Free Remote Code Execution Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.695
CVE-2021-39837
Adobe Acrobat Reader DC AcroForm deleteItemAt Use-After-Free Remote Code Execution Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.652
CVE-2021-39838
Adobe Acrobat Reader DC AcroForm buttonGetCaption Use-After-Free Remote Code Execution Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.652
CVE-2021-39839
Adobe Acrobat Reader DC AcroForm getItemAt Use-After-Free Remote Code Execution Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.652
CVE-2023-21608
Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability
Published 2023-01-18 · Analyzed
7.8KEVEPSS 0.615
CVE-2021-40728
Adobe Acrobat Reader DC Use After Free Arbitrary Code Execution
Published 2021-10-15 · Modified
7.8EPSS 0.546
CVE-2020-24435
Acrobat Reader DC Heap-based Buffer Overflow Could Lead to Arbitrary Code Execution
Published 2020-11-05 · Modified
7.8EPSS 0.527
CVE-2021-39840
Adobe Acrobat Reader DC AcroForm Field Use-After-Free Remote Code Execution Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.506
CVE-2020-24437
Acrobat Reader DC Use-After-Free Vulnerability Could Lead to Arbitrary Code Execution
Published 2020-11-05 · Modified
7.8EPSS 0.465
CVE-2021-28554
Adobe Acrobat Reader DC Path Parsing Out-Of-Bounds Read could lead to arbitrary code execution
Published 2021-08-24 · Modified
7.8EPSS 0.460
CVE-2021-44701
Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2022-01-14 · Modified
7.8EPSS 0.209
CVE-2020-24430
Acrobat Pro DC Use-After-Free vulnerability Could Lead to Arbitrary Code Execution
Published 2020-11-05 · Modified
7.8EPSS 0.187
CVE-2021-39842
Adobe Acrobat Reader DC messageHandler.OnMessage Use-After-Free Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.174
CVE-2020-24436
Acrobat Pro DC PDF Export Out-Of-Bounds Write Vulnerability Could Lead to Arbitrary Code Execution
Published 2020-11-05 · Modified
7.8EPSS 0.170
← Prev21 / 36Next →