VendorsAdobeacrobat_readerall versions
Vulnerabilities

Adobe Acrobat Reader

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1090CVEs
CVE-2018-4907
An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the TIFF processing in the XPS module. A successful attack can lead to sensitive data exposure.
Published 2018-02-27 · Modified
6.5EPSS 0.108
CVE-2018-4908
An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the TTF font processing in the XPS module. A successful attack can lead to sensitive data exposure.
Published 2018-02-27 · Modified
6.5EPSS 0.108
CVE-2018-4909
An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion module when processing metadata in JPEG images. A successful attack can lead to sensitive data exposure.
Published 2018-02-27 · Modified
6.5EPSS 0.108
CVE-2018-4912
An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion module that handles JPEG 2000 data. A successful attack can lead to sensitive data exposure.
Published 2018-02-27 · Modified
6.5EPSS 0.108
CVE-2017-11230
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the JPEG 2000 engine. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
6.5EPSS 0.101
CVE-2017-11244
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to transformation of blocks of pixels. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
6.5EPSS 0.101
CVE-2018-4999
Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, and 2015.006.30394 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Published 2018-07-09 · Modified
6.5EPSS 0.098
CVE-2017-11236
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the internal handling of UTF-16 literal strings. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
6.5EPSS 0.092
CVE-2017-11217
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to drawing of Unicode text strings. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
6.5EPSS 0.084
CVE-2017-11232
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability when processing Enhanced Metafile Format (EMF) data related to brush manipulation. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
6.5EPSS 0.076
CVE-2017-11233
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to block transfer of pixels. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
6.5EPSS 0.076
CVE-2017-11238
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to curve drawing. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
6.5EPSS 0.076
CVE-2017-11239
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to text strings. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
6.5EPSS 0.076
CVE-2017-11243
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the XSLT engine. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
6.5EPSS 0.076
CVE-2017-11245
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
6.5EPSS 0.076
CVE-2017-11246
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when parsing JPEG data. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
6.5EPSS 0.076
CVE-2017-11248
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to pixel block transfer. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
6.5EPSS 0.076
CVE-2017-11249
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when parsing an invalid Enhanced Metafile Format (EMF) record. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
6.5EPSS 0.076
CVE-2017-11252
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the Adobe Graphics Manager (AGM) module. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
6.5EPSS 0.076
CVE-2017-11255
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing TIFF color map data. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
6.5EPSS 0.076
CVE-2017-11258
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data and the embedded GIF image. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
6.5EPSS 0.076
CVE-2017-11265
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the Adobe Graphics Manager module. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
6.5EPSS 0.076
CVE-2017-11242
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to line segments. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
6.5EPSS 0.070
CVE-2017-16369
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a Same Origin Policy security bypass vulnerability, affecting files on the local system, etc.
Published 2017-12-09 · Modified
6.5EPSS 0.069
CVE-2017-16419
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The issue is a stack exhaustion problem within the JavaScript API, where the computation does not correctly control the amount of recursion that can happen with respect to system resources.
Published 2017-12-09 · Modified
6.5EPSS 0.068
CVE-2017-16361
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a security bypass vulnerability when handling XFDF files.
Published 2017-12-09 · Modified
6.5EPSS 0.054
CVE-2021-28555
Adobe Acrobat Reader out-of-bounds Read could lead to information disclosure
Published 2021-09-02 · Modified
6.5EPSS 0.028
CVE-2021-39855
Adobe Acrobat Reader DC NTLMv2 SSO Information Disclosure via src Parameter
Published 2021-09-29 · Modified
6.5EPSS 0.024
CVE-2021-39856
Adobe Acrobat Reader DC NTLMv2 SSO Information Disclosure via LoadFile
Published 2021-09-29 · Modified
6.5EPSS 0.024
CVE-2021-28546
Acrobat Reader DC Missing Support for Integrity Check
Published 2021-04-01 · Modified
6.5EPSS 0.014
CVE-2014-9150
Race condition in the MoveFileEx call hook feature in Adobe Reader and Acrobat 11.x before 11.0.09 on Windows allows attackers to bypass a sandbox protection mechanism, and consequently write to files in arbitrary locations, via an NTFS junction attack, a similar issue to CVE-2014-0568.
Published 2014-11-30 · Modified
6.4EPSS 0.023
CVE-2022-28244
Adobe Acrobat Reader DC CSP Bypass Leads To Privilege Escalation
Published 2022-05-11 · Modified
6.3EPSS 0.036
CVE-2024-49535
Acrobat Reader | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
Published 2024-12-10 · Analyzed
6.3EPSS 0.004
CVE-2007-5666
Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.1 and earlier allows local users to execute arbitrary code via a malicious Security Provider library in the reader's current working directory. NOTE: this issue might be subsumed by CVE-2008-0655.
Published 2008-02-12 · Modified
6.2EPSS 0.014
CVE-2021-39845
Adobe Acrobat Reader Page Tree Node Recursive Stack Overflow
Published 2021-09-29 · Modified
6.1EPSS 0.026
CVE-2021-39846
Adobe Acrobat Reader /Parent Property Recursive Stack Overflow
Published 2021-09-29 · Modified
6.1EPSS 0.026
CVE-2020-24431
Acrobat Reader DC for macOS Dynamic Library Injection Vulnerability
Published 2020-11-05 · Modified
5.8EPSS 0.016
CVE-2021-44715
Adobe Acrobat Reader DC Out-of-Bounds Read Information Disclosure Vulnerability
Published 2022-01-14 · Modified
5.5EPSS 0.147
CVE-2022-28246
Adobe Acrobat Reader DC Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2022-05-11 · Modified
5.5EPSS 0.101
CVE-2022-28258
Adobe Acrobat Reader DC Annotation Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2022-05-11 · Modified
5.5EPSS 0.101
← Prev22 / 28Next →