VendorsAdobeacrobat_readerall versions
Vulnerabilities

Adobe Acrobat Reader

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1090CVEs
CVE-2025-54255
Acrobat Reader | Violation of Secure Design Principles (CWE-657)
Published 2025-09-09 · Analyzed
4.0EPSS 0.003
CVE-2008-0883
acroread in Adobe Acrobat Reader 8.1.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files related to SSL certificate handling.
Published 2008-03-06 · Modified
3.7EPSS 0.008
CVE-2025-64787
Acrobat Reader | Improper Verification of Cryptographic Signature (CWE-347)
Published 2025-12-09 · Analyzed
3.3EPSS 0.004
CVE-2025-64786
Acrobat Reader | Improper Verification of Cryptographic Signature (CWE-347)
Published 2025-12-09 · Analyzed
3.3EPSS 0.004
CVE-2020-24439
Acrobat Reader DC for macOS Signature Validation Bypass
Published 2020-11-05 · Modified
2.8EPSS 0.006
CVE-2005-1347
** UNVERIFIABLE ** NOTE: this issue describes a problem that can not be independently verified as of 20050421. Adobe Acrobat reader (AcroRd32.exe) 6.0 and earlier allows remote attackers to cause a denial of service ("Invalid-ID-Handle-Error" error) and modify memory beginning at a particular address, possibly allowing the execution of arbitrary code, via a crafted PDF file. NOTE: the vendor has stated that the reporter refused to provide sufficient details to confirm the issue. In addition, due to the lack of details in the original advisory, an independent verification is not possible. Finally, the reliability of the original reporter is unknown. This item has only been assigned a CVE identifier for tracking purposes, and to serve as a concrete example of the newly defined UNVERIFIABLE and PRERELEASE content decisions in CVE, which must be discussed by the Editorial Board. Without additional details or independent verification by reliable sources, it is highly likely that this item will be REJECTED.
Published 2005-04-28 · Modified
2.6EPSS 0.052
CVE-2005-0492
Adobe Acrobat Reader 6.0.3 and 7.0.0 allows remote attackers to cause a denial of service (application crash) via a PDF file that contains a negative Count value in the root page node.
Published 2005-02-21 · Modified
2.6EPSS 0.018
CVE-2002-1764
acroread in Adobe Acrobat Reader 4.05 on Linux allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Published 2005-06-21 · Modified
2.1EPSS 0.009
CVE-2005-1841
The control for Adobe Reader 5.0.9 and 5.0.10 on Linux, Solaris, HP-UX, and AIX creates temporary files with the permissions as specified in a user's umask, which could allow local users to read PDF documents of that user if the umask allows it.
Published 2005-07-07 · Modified
2.1EPSS 0.007
CVE-2015-7829
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows mishandle junctions in the Synchronizer directory, which allows attackers to delete arbitrary files via Adobe Collaboration Sync, a related issue to CVE-2015-2428.
Published 2015-10-14 · Modified
1.9EPSS 0.011
← Prev28 / 28