VendorsAdobeacrobatall versions
Vulnerabilities

Adobe Acrobat

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1414CVEs
CVE-2014-0521
Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X do not properly implement JavaScript APIs, which allows remote attackers to obtain sensitive information via a crafted PDF document.
Published 2014-05-14 · Modified
4.3EPSS 0.099
CVE-2022-28252
Adobe Acrobat Reader DC Annotation Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2022-05-11 · Modified
4.3EPSS 0.093
CVE-2009-2992
An unspecified ActiveX control in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 does not properly validate input, which allows attackers to cause a denial of service via unknown vectors.
Published 2009-10-19 · Modified
4.3EPSS 0.049
CVE-2010-3657
Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2010-3656.
Published 2010-10-06 · Modified
4.3EPSS 0.045
CVE-2010-3656
Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2010-3657.
Published 2010-10-06 · Modified
4.3EPSS 0.045
CVE-2021-40729
Adobe Acrobat Reader DC PDF Out-of-Bound Read Vulnerability Information Disclosure
Published 2021-10-15 · Modified
4.3EPSS 0.043
CVE-2015-5583
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allow attackers to bypass intended sandbox restrictions and obtain sensitive PDF information by launching a print job on a remote printer, a different vulnerability than CVE-2015-6705, CVE-2015-6706, and CVE-2015-7624.
Published 2015-10-14 · Modified
4.3EPSS 0.040
CVE-2017-3032
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the JPEG 2000 code-stream parser.
Published 2017-04-12 · Modified
4.3EPSS 0.040
CVE-2021-40730
Adobe Acrobat Reader DC JPEG2000 Parsing Use-After-Free Information Disclosure Vulnerability
Published 2021-10-15 · Modified
4.3EPSS 0.039
CVE-2020-24438
Acrobat Reader DC Use-After-Free Vulnerability Could Lead to Information Disclosure
Published 2020-11-05 · Modified
4.3EPSS 0.039
CVE-2015-6699
The addForegroundSprite function in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to obtain sensitive information from process memory via invalid arguments, a different vulnerability than CVE-2015-6697, CVE-2015-6700, CVE-2015-6701, CVE-2015-6702, CVE-2015-6703, and CVE-2015-6704.
Published 2015-10-14 · Modified
4.3EPSS 0.038
CVE-2015-6701
The ambientIlluminationColor property implementation in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to obtain sensitive information from process memory via a function call, a different vulnerability than CVE-2015-6697, CVE-2015-6699, CVE-2015-6700, CVE-2015-6702, CVE-2015-6703, and CVE-2015-6704.
Published 2015-10-14 · Modified
4.3EPSS 0.038
CVE-2015-6702
The createSquareMesh function in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to obtain sensitive information from process memory via invalid arguments, a different vulnerability than CVE-2015-6697, CVE-2015-6699, CVE-2015-6700, CVE-2015-6701, CVE-2015-6703, and CVE-2015-6704.
Published 2015-10-14 · Modified
4.3EPSS 0.038
CVE-2015-6703
The loadFlashMovie function in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to obtain sensitive information from process memory via invalid arguments, a different vulnerability than CVE-2015-6697, CVE-2015-6699, CVE-2015-6700, CVE-2015-6701, CVE-2015-6702, and CVE-2015-6704.
Published 2015-10-14 · Modified
4.3EPSS 0.038
CVE-2015-6704
The animations property implementation in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to obtain sensitive information from process memory via a function call, a different vulnerability than CVE-2015-6697, CVE-2015-6699, CVE-2015-6700, CVE-2015-6701, CVE-2015-6702, and CVE-2015-6703.
Published 2015-10-14 · Modified
4.3EPSS 0.038
CVE-2015-5107
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to obtain sensitive information via unspecified vectors.
Published 2015-07-15 · Modified
4.3EPSS 0.038
CVE-2009-2995
Integer overflow in Adobe Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows attackers to cause a denial of service via unspecified vectors.
Published 2009-10-19 · Modified
4.3EPSS 0.038
CVE-2011-2107
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.181.22 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.22 and earlier on Android, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "universal cross-site scripting vulnerability."
Published 2011-06-07 · Modified
4.3EPSS 0.036
CVE-2009-2988
Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which allows attackers to cause a denial of service via unspecified vectors.
Published 2009-10-19 · Modified
4.3EPSS 0.035
CVE-2011-2104
Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allow attackers to cause a denial of service (memory corruption) via unspecified vectors.
Published 2011-06-16 · Modified
4.3EPSS 0.035
CVE-2009-2979
Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 do not properly perform XMP-XML entity expansion, which allows remote attackers to cause a denial of service via a crafted document.
Published 2009-10-19 · Modified
4.3EPSS 0.032
CVE-2017-3031
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the XSLT engine.
Published 2017-04-12 · Modified
4.3EPSS 0.032
CVE-2017-3033
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability when handling JPEG 2000 code-stream tile data.
Published 2017-04-12 · Modified
4.3EPSS 0.032
CVE-2011-0587
Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-0604.
Published 2011-02-10 · Modified
4.3EPSS 0.032
CVE-2011-0604
Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-0587.
Published 2011-02-10 · Modified
4.3EPSS 0.032
CVE-2021-39844
Adobe Acrobat Reader CalRGB Out-of-Bounds Read Vulnerability
Published 2021-09-29 · Modified
4.3EPSS 0.031
CVE-2020-24426
Acrobat Reader DC Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2020-11-05 · Modified
4.3EPSS 0.031
CVE-2020-24434
Acrobat Pro DC Out-Of-Bounds Read Vulnerability Could Lead to Information Disclosure
Published 2020-11-05 · Modified
4.3EPSS 0.031
CVE-2017-3020
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the weblink module.
Published 2017-04-12 · Modified
4.3EPSS 0.028
CVE-2017-3029
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability when handling a JPEG 2000 code-stream.
Published 2017-04-12 · Modified
4.3EPSS 0.028
CVE-2010-0190
Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2010-04-14 · Modified
4.3EPSS 0.027
CVE-2009-2987
Unspecified vulnerability in an ActiveX control in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 on Windows allows remote attackers to cause a denial of service via unknown vectors.
Published 2009-10-19 · Modified
4.3EPSS 0.026
CVE-2021-21034
Acrobat Reader DC Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2021-02-11 · Modified
4.3EPSS 0.026
CVE-2021-44714
Adobe Acrobat Reader Missing Custom Protocols in Warning Message Prompts
Published 2022-01-14 · Modified
4.3EPSS 0.026
CVE-2021-39857
Adobe Acrobat Reader DC Information Disclosure via ActiveX LoadFile
Published 2021-09-29 · Modified
4.3EPSS 0.025
CVE-2021-39858
Adobe Acrobat Pro DC PostScript File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2021-09-29 · Modified
4.3EPSS 0.025
CVE-2014-5315
Cross-site scripting (XSS) vulnerability in the Help page in Adobe Acrobat 9.5.2 and earlier and ColdFusion 8.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2014-09-26 · Modified
4.3EPSS 0.025
CVE-2014-0562
Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on OS X allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)."
Published 2014-09-17 · Modified
4.3EPSS 0.025
CVE-2017-3021
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the JPEG 2000 parser engine.
Published 2017-04-12 · Modified
4.3EPSS 0.025
CVE-2020-24427
Acrobat Reader DC Codec Input Validation Vulnerability Could Lead to Information Disclosure
Published 2020-11-05 · Modified
4.3EPSS 0.024
← Prev35 / 36Next →