VendorsAdobeacrobatall versions
Vulnerabilities

Adobe Acrobat

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1414CVEs
CVE-2024-34099
ZDI-CAN-XXXX: [Pwn2Own] Acrobat sandbox bypass part 2 of 2
Published 2024-05-15 · Analyzed
7.8EPSS 0.004
CVE-2023-22240
ZDI-CAN-19517: Adobe Acrobat Reader DC AcroForm Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-01-27 · Modified
7.8EPSS 0.004
CVE-2023-22241
ZDI-CAN-19516: Adobe Acrobat Reader DC AcroForm Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-01-27 · Modified
7.8EPSS 0.004
CVE-2025-27159
Acrobat Reader | Use After Free (CWE-416)
Published 2025-03-11 · Analyzed
7.8EPSS 0.004
CVE-2025-27160
Acrobat Reader | Use After Free (CWE-416)
Published 2025-03-11 · Analyzed
7.8EPSS 0.004
CVE-2025-27174
Acrobat Reader | Use After Free (CWE-416)
Published 2025-03-11 · Analyzed
7.8EPSS 0.004
CVE-2024-34098
ZDI-CAN-XXXX: [Pwn2Own] Acrobat sandbox bypass part 1 of 2
Published 2024-05-15 · Analyzed
7.8EPSS 0.004
CVE-2021-21088
Adobe Acrobat Pro DC Use-After-Free Remote Code Execution Vulnerability
Published 2023-09-06 · Modified
7.8EPSS 0.003
CVE-2025-54257
Acrobat Reader | Use After Free (CWE-416)
Published 2025-09-09 · Modified
7.8EPSS 0.003
CVE-2026-81992
Acrobat Reader | Heap-based Buffer Overflow (CWE-122)
Published 2026-09-08 · Analyzed
7.8EPSS 0.003
CVE-2026-47959
Acrobat Reader | Stack-based Buffer Overflow (CWE-121)
Published 2026-06-09 · Analyzed
7.8EPSS 0.003
CVE-2026-48373
Acrobat Reader | Heap-based Buffer Overflow (CWE-122)
Published 2026-07-17 · Analyzed
7.8EPSS 0.003
CVE-2026-47952
Acrobat Reader | Heap-based Buffer Overflow (CWE-122)
Published 2026-06-09 · Analyzed
7.8EPSS 0.003
CVE-2025-27161
Acrobat Reader | Out-of-bounds Read (CWE-125)
Published 2025-03-11 · Analyzed
7.8EPSS 0.003
CVE-2025-27162
Acrobat Reader | Access of Uninitialized Pointer (CWE-824)
Published 2025-03-11 · Analyzed
7.8EPSS 0.003
CVE-2024-34122
T5 Acrobat Vulnerability - Exploitable crash in DecodeTile
Published 2024-07-02 · Modified
7.8EPSS 0.003
CVE-2026-81987
Acrobat Reader | Integer Overflow or Wraparound (CWE-190)
Published 2026-09-08 · Analyzed
7.8EPSS 0.003
CVE-2022-44512
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2024-12-18 · Analyzed
7.8EPSS 0.003
CVE-2022-44513
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2024-12-18 · Analyzed
7.8EPSS 0.003
CVE-2026-80161
Acrobat Reader | Access of Resource Using Incompatible Type ('Type Confusion') (CWE-843)
Published 2026-09-08 · Analyzed
7.8EPSS 0.003
CVE-2026-79907
Acrobat Reader | Double Free (CWE-415)
Published 2026-09-08 · Analyzed
7.8EPSS 0.003
CVE-2026-47911
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2026-06-09 · Analyzed
7.8EPSS 0.003
CVE-2026-81980
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2026-09-08 · Analyzed
7.8EPSS 0.003
CVE-2026-81979
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2026-09-08 · Analyzed
7.8EPSS 0.003
CVE-2026-81983
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2026-09-08 · Analyzed
7.8EPSS 0.003
CVE-2026-79908
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2026-09-08 · Analyzed
7.8EPSS 0.003
CVE-2026-81981
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2026-09-08 · Analyzed
7.8EPSS 0.003
CVE-2026-47965
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2026-06-12 · Analyzed
7.8EPSS 0.003
CVE-2020-24428
Acrobat Reader DC for macOS Race Condition Vulnerability Could Lead to Privilege Escalation
Published 2020-11-05 · Modified
7.7EPSS 0.023
CVE-2026-47937
Acrobat Reader | Uncontrolled Search Path Element (CWE-427)
Published 2026-06-09 · Analyzed
7.7EPSS 0.003
CVE-2000-0713
Buffer overflow in Adobe Acrobat 4.05, Reader, Business Tools, and Fill In products that handle PDF files allows attackers to execute arbitrary commands via a long /Registry or /Ordering specifier.
Published 2000-09-21 · Modified
7.6EPSS 0.049
CVE-2003-0434
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
Published 2003-06-18 · Modified
7.51 PoCEPSS 0.409
CVE-2005-1306
The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."
Published 2005-06-15 · Modified
7.51 PoCEPSS 0.145
CVE-2005-2470
Buffer overflow in a "core application plug-in" for Adobe Reader 5.1 through 7.0.2 and Acrobat 5.0 through 7.0.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.
Published 2005-08-16 · Modified
7.5EPSS 0.132
CVE-2016-1079
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to obtain sensitive information from process memory via unspecified vectors, a different vulnerability than CVE-2016-1092.
Published 2016-05-11 · Modified
7.5EPSS 0.100
CVE-2015-3055
Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3053, CVE-2015-3054, CVE-2015-3059, and CVE-2015-3075.
Published 2015-05-13 · Modified
7.5EPSS 0.098
CVE-2008-4815
Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.2 and earlier on Unix and Linux allows attackers to gain privileges via a Trojan Horse program in an unspecified directory that is associated with an insecure RPATH.
Published 2008-11-05 · Modified
7.5EPSS 0.078
CVE-2015-6713
The Function call implementation in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-6707, CVE-2015-6708, CVE-2015-6709, CVE-2015-6710, CVE-2015-6711, CVE-2015-6712, CVE-2015-6714, CVE-2015-6715, CVE-2015-6716, CVE-2015-6717, CVE-2015-6718, CVE-2015-6719, CVE-2015-6720, CVE-2015-6721, CVE-2015-6722, CVE-2015-6723, CVE-2015-6724, CVE-2015-6725, CVE-2015-7614, CVE-2015-7616, CVE-2015-7618, CVE-2015-7619, CVE-2015-7620, and CVE-2015-7623.
Published 2015-10-14 · Modified
7.5EPSS 0.076
CVE-2004-0632
Adobe Reader 6.0 does not properly handle null characters when splitting a filename path into components, which allows remote attackers to execute arbitrary code via a file with a long extension that is not normally handled by Reader, triggering a buffer overflow.
Published 2004-07-16 · Modified
7.5EPSS 0.072
CVE-2004-0629
Buffer overflow in the ActiveX component (pdf.ocx) for Adobe Acrobat 5.0.5 and Acrobat Reader, and possibly other versions, allows remote attackers to execute arbitrary code via a URI for a PDF file with a null terminator (%00) followed by a long string.
Published 2004-08-18 · Modified
7.5EPSS 0.071
← Prev26 / 36Next →