VendorsAdobeacrobat_readerany version
Vulnerabilities

Adobe Acrobat Reader any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

766CVEs
CVE-2022-44514
Acrobat Reader | Use After Free (CWE-416)
Published 2024-12-18 · Analyzed
7.8EPSS 0.004
CVE-2022-44518
Acrobat Reader | Use After Free (CWE-416)
Published 2024-12-18 · Analyzed
7.8EPSS 0.004
CVE-2022-44520
Acrobat Reader | Use After Free (CWE-416)
Published 2024-12-18 · Analyzed
7.8EPSS 0.004
CVE-2024-34099
ZDI-CAN-XXXX: [Pwn2Own] Acrobat sandbox bypass part 2 of 2
Published 2024-05-15 · Analyzed
7.8EPSS 0.004
CVE-2023-22240
ZDI-CAN-19517: Adobe Acrobat Reader DC AcroForm Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-01-27 · Modified
7.8EPSS 0.004
CVE-2023-22241
ZDI-CAN-19516: Adobe Acrobat Reader DC AcroForm Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-01-27 · Modified
7.8EPSS 0.004
CVE-2025-27174
Acrobat Reader | Use After Free (CWE-416)
Published 2025-03-11 · Analyzed
7.8EPSS 0.004
CVE-2024-34098
ZDI-CAN-XXXX: [Pwn2Own] Acrobat sandbox bypass part 1 of 2
Published 2024-05-15 · Analyzed
7.8EPSS 0.004
CVE-2025-27159
Acrobat Reader | Use After Free (CWE-416)
Published 2025-03-11 · Analyzed
7.8EPSS 0.004
CVE-2025-27160
Acrobat Reader | Use After Free (CWE-416)
Published 2025-03-11 · Analyzed
7.8EPSS 0.004
CVE-2021-21088
Adobe Acrobat Pro DC Use-After-Free Remote Code Execution Vulnerability
Published 2023-09-06 · Modified
7.8EPSS 0.003
CVE-2025-54257
Acrobat Reader | Use After Free (CWE-416)
Published 2025-09-09 · Modified
7.8EPSS 0.003
CVE-2026-47959
Acrobat Reader | Stack-based Buffer Overflow (CWE-121)
Published 2026-06-09 · Analyzed
7.8EPSS 0.003
CVE-2025-27161
Acrobat Reader | Out-of-bounds Read (CWE-125)
Published 2025-03-11 · Analyzed
7.8EPSS 0.003
CVE-2025-27162
Acrobat Reader | Access of Uninitialized Pointer (CWE-824)
Published 2025-03-11 · Analyzed
7.8EPSS 0.003
CVE-2022-44513
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2024-12-18 · Analyzed
7.8EPSS 0.003
CVE-2022-44512
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2024-12-18 · Analyzed
7.8EPSS 0.003
CVE-2026-47911
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2026-06-09 · Analyzed
7.8EPSS 0.003
CVE-2020-24428
Acrobat Reader DC for macOS Race Condition Vulnerability Could Lead to Privilege Escalation
Published 2020-11-05 · Modified
7.7EPSS 0.023
CVE-2007-0046
Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute arbitrary code by causing an error via a javascript: URI call to document.write in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.
Published 2007-01-03 · Modified
7.51 PoCEPSS 0.559
CVE-2008-4815
Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.2 and earlier on Unix and Linux allows attackers to gain privileges via a Trojan Horse program in an unspecified directory that is associated with an insecure RPATH.
Published 2008-11-05 · Modified
7.5EPSS 0.078
CVE-2015-6713
The Function call implementation in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-6707, CVE-2015-6708, CVE-2015-6709, CVE-2015-6710, CVE-2015-6711, CVE-2015-6712, CVE-2015-6714, CVE-2015-6715, CVE-2015-6716, CVE-2015-6717, CVE-2015-6718, CVE-2015-6719, CVE-2015-6720, CVE-2015-6721, CVE-2015-6722, CVE-2015-6723, CVE-2015-6724, CVE-2015-6725, CVE-2015-7614, CVE-2015-7616, CVE-2015-7618, CVE-2015-7619, CVE-2015-7620, and CVE-2015-7623.
Published 2015-10-14 · Modified
7.5EPSS 0.076
CVE-2003-0508
Buffer overflow in the WWWLaunchNetscape function of Adobe Acrobat Reader (acroread) 5.0.7 and earlier allows remote attackers to execute arbitrary code via a .pdf file with a long mailto link.
Published 2003-07-04 · Modified
7.51 PoCEPSS 0.070
CVE-2017-16366
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a security bypass vulnerability in the AcroPDF plugin.
Published 2017-12-09 · Modified
7.5EPSS 0.059
CVE-2015-4446
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and perform a transition from Low Integrity to Medium Integrity via unspecified vectors, a different vulnerability than CVE-2015-5090 and CVE-2015-5106.
Published 2015-07-15 · Modified
7.5EPSS 0.051
CVE-2006-1627
Adobe Document Server for Reader Extensions 6.0 does not provide proper access control, which allows remote authenticated users to perform privileged actions by modifying the (1) actionID and (2) pageID parameters. NOTE: due to an error during reservation, this identifier was inadvertently associated with multiple issues. Other CVE identifiers have been assigned to handle other problems that are covered by the same disclosure.
Published 2006-04-13 · Modified
7.5EPSS 0.043
CVE-2024-34129
Acrobat Android : OverSecured Finding : Overwriting arbitrary files via attacker-controlled output file paths
Published 2024-06-13 · Modified
7.5EPSS 0.003
CVE-2022-28247
Adobe Acrobat Uninstaller Hard Link Leads To Remote Code Execution
Published 2022-05-11 · Modified
7.3EPSS 0.005
CVE-2015-5090
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and perform a transition from Low Integrity to Medium Integrity via unspecified vectors, a different vulnerability than CVE-2015-4446 and CVE-2015-5106.
Published 2015-07-15 · Modified
7.2EPSS 0.011
CVE-2020-29075
PDF Injection BlackHat Talk
Published 2021-02-23 · Modified
7.1EPSS 0.079
CVE-2024-39420
Acrobat Reader | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)
Published 2024-08-14 · Modified
7.0EPSS 0.035
CVE-2024-39425
Security vulnerability in AdobeARMHelper
Published 2024-08-14 · Analyzed
7.0EPSS 0.002
CVE-2007-0103
The Adobe PDF specification 1.3, as implemented by Adobe Acrobat before 8.0.0, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.
Published 2007-01-09 · Modified
6.81 PoCEPSS 0.155
CVE-2007-0047
CRLF injection vulnerability in Adobe Acrobat Reader Plugin before 8.0.0, when used with the Microsoft.XMLHTTP ActiveX object in Internet Explorer, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the javascript: URI in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.
Published 2007-01-03 · Modified
6.8EPSS 0.091
CVE-2015-8458
Heap-based buffer overflow in AGM.dll in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to execute arbitrary code via a multiple-layer PDF document, a different vulnerability than CVE-2015-6696 and CVE-2015-6698.
Published 2015-12-21 · Modified
6.8EPSS 0.083
CVE-2015-5110
Stack-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors.
Published 2015-07-15 · Modified
6.8EPSS 0.082
CVE-2015-6696
Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-6698.
Published 2015-10-14 · Modified
6.8EPSS 0.078
CVE-2015-6698
Heap-based buffer overflow in the AcroForm implementation in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-6696.
Published 2015-10-14 · Modified
6.8EPSS 0.078
CVE-2012-0777
The JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 on Mac OS X and Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Published 2012-04-10 · Modified
6.8EPSS 0.071
CVE-2015-7614
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions and execute arbitrary commands via an app.launchURL call, a different vulnerability than CVE-2015-6707, CVE-2015-6708, CVE-2015-6709, CVE-2015-6710, CVE-2015-6711, CVE-2015-6712, CVE-2015-6713, CVE-2015-6714, CVE-2015-6715, CVE-2015-6716, CVE-2015-6717, CVE-2015-6718, CVE-2015-6719, CVE-2015-6720, CVE-2015-6721, CVE-2015-6722, CVE-2015-6723, CVE-2015-6724, CVE-2015-6725, CVE-2015-7616, CVE-2015-7618, CVE-2015-7619, CVE-2015-7620, and CVE-2015-7623.
Published 2015-10-14 · Modified
6.8EPSS 0.070
← Prev12 / 20Next →