VendorsAdobeacrobatany version
Vulnerabilities

Adobe Acrobat any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1120CVEs
CVE-2009-1862
Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009.
Published 2009-07-23 · Analyzed
9.3KEVEPSS 0.212
CVE-2017-2949
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability in the XSLT engine. Successful exploitation could lead to arbitrary code execution.
Published 2017-01-11 · Modified
9.3EPSS 0.204
CVE-2017-3044
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the JPEG 2000 engine, related to image scaling. Successful exploitation could lead to arbitrary code execution.
Published 2017-04-12 · Modified
9.3EPSS 0.204
CVE-2017-3117
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in the plugin that handles links within the PDF. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
9.3EPSS 0.189
CVE-2009-2994
Buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors.
Published 2009-10-19 · Modified
9.31 PoCEPSS 0.186
CVE-2017-2960
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion engine, related to parsing of EXIF metadata. Successful exploitation could lead to arbitrary code execution.
Published 2017-01-11 · Modified
9.3EPSS 0.185
CVE-2022-27791
Adobe Acrobat Reader DC Font Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.178
CVE-2022-27799
Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.177
CVE-2017-16393
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the JavaScript engine. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to code corruption, control-flow hijack, or an information leak attack. Successful exploitation could lead to arbitrary code execution.
Published 2017-12-09 · Modified
9.3EPSS 0.169
CVE-2021-45062
Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-01-14 · Modified
9.3EPSS 0.165
CVE-2020-24433
Adobe Acrobat Reader DC Local Privilege Escalation via Installer Component
Published 2020-11-05 · Modified
9.3EPSS 0.159
CVE-2010-2884
Adobe Flash Player 10.1.82.76 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.92.10 on Android; authplay.dll in Adobe Reader and Acrobat 9.x before 9.4; and authplay.dll in Adobe Reader and Acrobat 8.x before 8.2.5 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in September 2010.
Published 2010-09-15 · Modified
9.3EPSS 0.156
CVE-2017-11220
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in an internal data structure. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
9.3EPSS 0.147
CVE-2017-11241
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to polygons. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
9.3EPSS 0.147
CVE-2008-0726
Integer overflow in Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via crafted arguments to the printSepsWithParams, which triggers memory corruption.
Published 2008-02-12 · Modified
9.3EPSS 0.146
CVE-2017-3055
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable heap overflow vulnerability in JPEG 2000 parsing of the fragment list tag. Successful exploitation could lead to arbitrary code execution.
Published 2017-04-12 · Modified
9.3EPSS 0.145
CVE-2017-3042
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable heap overflow vulnerability in image conversion, related to parsing offsets in TIFF files. Successful exploitation could lead to arbitrary code execution.
Published 2017-04-12 · Modified
9.3EPSS 0.145
CVE-2017-3123
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data drawing position definition. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
9.3EPSS 0.144
CVE-2022-27794
Adobe Acrobat Reader DC Font Parsing Uninitialized Variable Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.143
CVE-2017-3048
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable heap overflow vulnerability in the image conversion engine, related to internal scan line representation in TIFF files. Successful exploitation could lead to arbitrary code execution.
Published 2017-04-12 · Modified
9.3EPSS 0.137
CVE-2007-5663
Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via a crafted PDF file that calls an insecure JavaScript method in the EScript.api plug-in. NOTE: this issue might be subsumed by CVE-2008-0655.
Published 2008-02-12 · Modified
9.3EPSS 0.133
CVE-2017-16368
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability leads to a stack-based buffer overflow condition in the internal Unicode string manipulation module. It is triggered by an invalid PDF file, where a crafted Unicode string causes an out of bounds memory access of a stack allocated buffer, due to improper checks when manipulating an offset of a pointer to the buffer. Attackers can exploit the vulnerability and achieve arbitrary code execution if they can effectively control the accessible memory.
Published 2017-12-09 · Modified
9.3EPSS 0.132
CVE-2017-16396
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an incorrect length value in the TIFF processing module. Crafted input causes a mismatch between allocated buffer size and the access allowed by the computation. If an attacker can adequately control the accessible memory then this vulnerability can be leveraged to achieve arbitrary code execution.
Published 2017-12-09 · Modified
9.3EPSS 0.128
CVE-2017-16392
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an incorrect length value in the JPEG processing module. Crafted input with an unexpected JPEG file segment size causes a mismatch between allocated buffer size and the access allowed by the computation. If an attacker can adequately control the accessible memory then this vulnerability can be leveraged to achieve arbitrary code execution.
Published 2017-12-09 · Modified
9.3EPSS 0.128
CVE-2017-16395
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an incorrect length value in the image conversion module when processing Enhanced Metafile Format (EMF). Crafted EMF input (EMR_STRETCHDIBITS) causes a mismatch between allocated buffer size and the access allowed by the computation. If an attacker can adequately control the accessible memory then this vulnerability can be leveraged to achieve arbitrary code execution.
Published 2017-12-09 · Modified
9.3EPSS 0.128
CVE-2017-16385
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an incorrect length value in TIFF parsing during XPS conversion. Crafted TIFF image input causes a mismatch between allocated buffer size and the access allowed by the computation. If an attacker can adequately control the accessible memory then this vulnerability can be leveraged to achieve arbitrary code execution.
Published 2017-12-09 · Modified
9.3EPSS 0.128
CVE-2017-16381
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an incorrect length value when processing TIFF files embedded within an XPS document. Crafted TIFF image input causes a mismatch between allocated buffer size and the access allowed by the computation. If an attacker can adequately control the accessible memory then this vulnerability can be leveraged to achieve arbitrary code execution.
Published 2017-12-09 · Modified
9.3EPSS 0.128
CVE-2017-11259
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
9.3EPSS 0.128
CVE-2022-24102
Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.126
CVE-2022-28232
Adobe Acrobat Reader DC Collab Object Use-After-Free Information Disclosure Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.125
CVE-2022-28230
Adobe Acrobat Reader DC AcroForm calculateNow Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.125
CVE-2022-27796
Adobe Acrobat Reader DC AcroForm isBoxChecked Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.125
CVE-2022-27785
Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.125
CVE-2022-28233
Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.125
CVE-2022-28240
Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.125
CVE-2009-2983
Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.
Published 2009-10-19 · Modified
9.31 PoCEPSS 0.122
CVE-2022-27786
Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.121
CVE-2022-28238
Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.119
CVE-2022-27790
Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.119
CVE-2008-4814
Unspecified vulnerability in a JavaScript method in Adobe Reader and Acrobat 8.1.2 and earlier, and before 7.1.1, allows remote attackers to execute arbitrary code via unknown vectors, related to an "input validation issue."
Published 2008-11-05 · Modified
9.3EPSS 0.119
← Prev8 / 28Next →