VendorsAdobeacrobatany version
Vulnerabilities

Adobe Acrobat any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1120CVEs
CVE-2026-47926
Acrobat Reader | Out-of-bounds Read (CWE-125)
Published 2026-06-09 · Analyzed
5.5EPSS 0.003
CVE-2026-81991
Acrobat Reader | Out-of-bounds Read (CWE-125)
Published 2026-09-08 · Analyzed
5.5EPSS 0.003
CVE-2026-81977
Acrobat Reader | Integer Underflow (Wrap or Wraparound) (CWE-191)
Published 2026-09-08 · Analyzed
5.5EPSS 0.003
CVE-2026-80160
Acrobat Reader | Out-of-bounds Read (CWE-125)
Published 2026-09-08 · Analyzed
5.5EPSS 0.003
CVE-2026-81978
Acrobat Reader | Out-of-bounds Read (CWE-125)
Published 2026-09-08 · Analyzed
5.5EPSS 0.003
CVE-2026-81982
Acrobat Reader | Out-of-bounds Read (CWE-125)
Published 2026-09-08 · Analyzed
5.5EPSS 0.003
CVE-2026-79910
Acrobat Reader | Out-of-bounds Read (CWE-125)
Published 2026-09-08 · Analyzed
5.5EPSS 0.003
CVE-2026-47925
Acrobat Reader | Integer Overflow or Wraparound (CWE-190)
Published 2026-06-09 · Analyzed
5.5EPSS 0.003
CVE-2026-82001
Acrobat Reader | Uncontrolled Resource Consumption (CWE-400)
Published 2026-09-08 · Analyzed
5.5EPSS 0.002
CVE-2025-43579
Acrobat Reader | Information Exposure (CWE-200)
Published 2025-06-10 · Analyzed
5.5EPSS 0.002
CVE-2026-27221
Acrobat Reader | Improper Certificate Validation (CWE-295)
Published 2026-03-10 · Analyzed
5.5EPSS 0.001
CVE-2021-28559
Adobe Acrobat Reader privacy violation vulnerability could lead to privilege escalation
Published 2021-09-02 · Modified
5.3EPSS 0.016
CVE-2009-3462
Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 on Unix, when Debug mode is enabled, allow attackers to execute arbitrary code via unspecified vectors, related to a "format bug."
Published 2009-10-19 · Modified
5.1EPSS 0.060
CVE-2007-0048
Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, when used with Internet Explorer, Google Chrome, or Opera, allows remote attackers to cause a denial of service (memory consumption) via a long sequence of # (hash) characters appended to a PDF URL, related to a "cross-site scripting issue."
Published 2007-01-03 · Modified
5.0EPSS 0.326
CVE-2009-3957
Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow attackers to cause a denial of service (NULL pointer dereference) via unspecified vectors.
Published 2010-01-13 · Modified
5.0EPSS 0.048
CVE-2015-6700
The setBackground function in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to obtain sensitive information from process memory via invalid arguments, a different vulnerability than CVE-2015-6697, CVE-2015-6699, CVE-2015-6701, CVE-2015-6702, CVE-2015-6703, and CVE-2015-6704.
Published 2015-10-14 · Modified
5.0EPSS 0.047
CVE-2014-8450
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2015-4449, CVE-2015-4450, CVE-2015-5088, CVE-2015-5089, and CVE-2015-5092.
Published 2015-07-15 · Modified
5.0EPSS 0.046
CVE-2015-4449
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2014-8450, CVE-2015-4450, CVE-2015-5088, CVE-2015-5089, and CVE-2015-5092.
Published 2015-07-15 · Modified
5.0EPSS 0.046
CVE-2015-4450
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2014-8450, CVE-2015-4449, CVE-2015-5088, CVE-2015-5089, and CVE-2015-5092.
Published 2015-07-15 · Modified
5.0EPSS 0.046
CVE-2015-5088
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2014-8450, CVE-2015-4449, CVE-2015-4450, CVE-2015-5089, and CVE-2015-5092.
Published 2015-07-15 · Modified
5.0EPSS 0.046
CVE-2015-5089
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2014-8450, CVE-2015-4449, CVE-2015-4450, CVE-2015-5088, and CVE-2015-5092.
Published 2015-07-15 · Modified
5.0EPSS 0.046
CVE-2015-5092
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2014-8450, CVE-2015-4449, CVE-2015-4450, CVE-2015-5088, and CVE-2015-5089.
Published 2015-07-15 · Modified
5.0EPSS 0.046
CVE-2015-6692
Buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to obtain sensitive information via unspecified vectors.
Published 2015-10-14 · Modified
5.0EPSS 0.034
CVE-2015-6705
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2015-5583, CVE-2015-6706, and CVE-2015-7624.
Published 2015-10-14 · Modified
5.0EPSS 0.031
CVE-2015-6706
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2015-5583, CVE-2015-6705, and CVE-2015-7624.
Published 2015-10-14 · Modified
5.0EPSS 0.031
CVE-2015-7624
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2015-5583, CVE-2015-6705, and CVE-2015-6706.
Published 2015-10-14 · Modified
5.0EPSS 0.031
CVE-2015-4443
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to cause a denial of service (NULL pointer dereference) via unspecified vectors, a different vulnerability than CVE-2015-4444.
Published 2015-07-15 · Modified
5.0EPSS 0.027
CVE-2015-4444
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to cause a denial of service (NULL pointer dereference) via unspecified vectors, a different vulnerability than CVE-2015-4443.
Published 2015-07-15 · Modified
5.0EPSS 0.027
CVE-2023-29299
Adobe Acrobat Reader Untrusted Search Path Application denial-of-service
Published 2023-08-10 · Modified
4.7EPSS 0.004
CVE-2021-21060
Acrobat Pro DC Improper File Parsing Could Lead to Information Disclosure
Published 2021-02-11 · Modified
4.6EPSS 0.016
CVE-2006-3452
Adobe Reader and Acrobat 6.0.4 and earlier, on Mac OSX, has insecure file and directory permissions, which allows local users to gain privileges by overwriting program files.
Published 2006-07-12 · Modified
4.6EPSS 0.006
CVE-2007-0044
Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."
Published 2007-01-03 · Modified
4.31 PoCEPSS 0.559
CVE-2007-0045
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka "Universal XSS (UXSS)."
Published 2007-01-03 · Modified
4.3EPSS 0.466
CVE-2017-3022
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability when parsing the header of a JPEG 2000 file.
Published 2017-04-12 · Modified
4.3EPSS 0.118
CVE-2022-28269
Adobe Acrobat Reader DC Annotation Use-After-Free Information Disclosure Vulnerability
Published 2022-05-11 · Modified
4.3EPSS 0.107
CVE-2022-28252
Adobe Acrobat Reader DC Annotation Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2022-05-11 · Modified
4.3EPSS 0.093
CVE-2009-2992
An unspecified ActiveX control in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 does not properly validate input, which allows attackers to cause a denial of service via unknown vectors.
Published 2009-10-19 · Modified
4.3EPSS 0.049
CVE-2021-40729
Adobe Acrobat Reader DC PDF Out-of-Bound Read Vulnerability Information Disclosure
Published 2021-10-15 · Modified
4.3EPSS 0.043
CVE-2015-5583
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allow attackers to bypass intended sandbox restrictions and obtain sensitive PDF information by launching a print job on a remote printer, a different vulnerability than CVE-2015-6705, CVE-2015-6706, and CVE-2015-7624.
Published 2015-10-14 · Modified
4.3EPSS 0.040
CVE-2017-3032
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the JPEG 2000 code-stream parser.
Published 2017-04-12 · Modified
4.3EPSS 0.040
← Prev27 / 28Next →