VendorsAdobeacrobat_readerall versions
Vulnerabilities

Adobe Acrobat Reader

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1090CVEs
CVE-2021-28565
Adobe Acrobat Reader out-of-bounds read could lead to information exposure
Published 2021-09-02 · Modified
9.3EPSS 0.039
CVE-2022-27800
Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.038
CVE-2022-28235
Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.038
CVE-2022-28237
Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.038
CVE-2022-27795
Adobe Acrobat Reader DC AcroForm isDefaultChecked Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.038
CVE-2022-27797
Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.038
CVE-2022-27801
Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.038
CVE-2022-27802
Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.038
CVE-2022-27789
Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.037
CVE-2010-2209
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.
Published 2010-06-30 · Modified
9.3EPSS 0.037
CVE-2010-2207
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2209, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.
Published 2010-06-30 · Modified
9.3EPSS 0.037
CVE-2010-2202
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.
Published 2010-06-30 · Modified
9.3EPSS 0.037
CVE-2010-2211
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, and CVE-2010-2212.
Published 2010-06-30 · Modified
9.3EPSS 0.037
CVE-2010-1295
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.
Published 2010-06-30 · Modified
9.3EPSS 0.037
CVE-2011-2105
Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allow attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted font data.
Published 2011-06-16 · Modified
9.3EPSS 0.037
CVE-2013-5325
Adobe Reader and Acrobat 11.x before 11.0.05 on Windows allow remote attackers to execute arbitrary JavaScript code in a javascript: URL via a crafted PDF document.
Published 2013-10-09 · Modified
9.3EPSS 0.036
CVE-2011-0610
The CoolType library in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Published 2011-05-03 · Modified
9.3EPSS 0.035
CVE-2021-21044
Acrobat Reader DC Out-Of-Bounds Write Vulnerability Could Lead To Arbitrary Code Execution
Published 2021-02-11 · Modified
9.3EPSS 0.035
CVE-2022-28242
Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.035
CVE-2009-4764
Adobe Reader 8.x and 9.x on Windows is able to execute EXE files that are embedded in a PDF document, which makes it easier for remote attackers to trick users into executing arbitrary code via a crafted document.
Published 2010-04-05 · Modified
9.3EPSS 0.035
CVE-2022-24103
Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.035
CVE-2022-28231
Adobe Acrobat Reader DC Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.034
CVE-2022-28239
Adobe Acrobat Reader DC Annotation Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.034
CVE-2011-0564
Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows use weak permissions for unspecified files, which allows attackers to gain privileges via unknown vectors.
Published 2011-02-10 · Modified
9.3EPSS 0.033
CVE-2022-28241
Adobe Acrobat Reader DC Doc Object Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.032
CVE-2022-27788
Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.030
CVE-2022-27798
Adobe Acrobat Reader DC zoomType Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.030
CVE-2009-2982
An unspecified certificate in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow remote attackers to conduct a "social engineering attack" via unknown vectors.
Published 2009-10-19 · Modified
9.3EPSS 0.028
CVE-2022-28838
Adobe Acrobat Pro DC Doc flattenPages Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.027
CVE-2021-21058
Acrobat Reader DC Memory Corruption Vulnerability Could Lead to Arbitrary Code Execution
Published 2021-02-11 · Modified
9.3EPSS 0.026
CVE-2021-21059
Acrobat Reader DC Buffer Overflow Vulnerability Could Lead to Arbitrary Code Execution
Published 2021-02-11 · Modified
9.3EPSS 0.026
CVE-2021-21062
Acrobat Reader DC Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution
Published 2021-02-11 · Modified
9.3EPSS 0.026
CVE-2021-21063
Acrobat Reader DC Buffer Overflow Vulnerability Could Lead to Arbitrary Code Execution
Published 2021-02-11 · Modified
9.3EPSS 0.026
CVE-2021-21045
Acrobat Reader DC Improper Installer Access Control Vulnerability Could Lead To Privilege Escalation
Published 2021-02-11 · Modified
9.3EPSS 0.018
CVE-2009-1597
Mozilla Firefox executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, which might allow remote attackers to bypass intended Adobe Acrobat JavaScript restrictions on accessing the document object, as demonstrated by a web site that permits PDF uploads by untrusted users, and therefore has a shared document.domain between the web site and this javascript: URI. NOTE: the researcher reports that Adobe's position is "a PDF file is active content."
Published 2009-05-11 · Modified
9.3EPSS 0.017
CVE-2009-1600
Apple Safari executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, which might allow remote attackers to bypass intended Adobe Acrobat JavaScript restrictions on accessing the document object, as demonstrated by a web site that permits PDF uploads by untrusted users, and therefore has a shared document.domain between the web site and this javascript: URI. NOTE: the researcher reports that Adobe's position is "a PDF file is active content."
Published 2009-05-11 · Modified
9.3EPSS 0.017
CVE-2009-1599
Opera executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, which might allow remote attackers to bypass intended Adobe Acrobat JavaScript restrictions on accessing the document object, as demonstrated by a web site that permits PDF uploads by untrusted users, and therefore has a shared document.domain between the web site and this javascript: URI. NOTE: the researcher reports that Adobe's position is "a PDF file is active content."
Published 2009-05-11 · Modified
9.3EPSS 0.017
CVE-2021-21017
Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution
Published 2021-02-11 · Analyzed
8.8KEVEPSS 0.863
CVE-2021-28560
Adobe Acrobat Reader heap corruption vulnerability could lead to arbitrary code execution
Published 2021-09-02 · Modified
8.8EPSS 0.669
CVE-2018-4904
An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability is an instance of a heap overflow vulnerability. The vulnerability is triggered by crafted TIFF data within an XPS file, which causes an out of bounds memory access. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code.
Published 2018-02-27 · Modified
8.8EPSS 0.428
← Prev13 / 28Next →